CVE-2006-0478
Last modified
CVE-2006-0478 is a vulnerability of currently unknown severity. CRE Loaded 6.15 allows remote attackers to perform privileged actions, including uploading and creating arbitrary files, via a direct request to files.php. NOTE: the vendor states "The initial announcement of this risk was made on our website... EPSS estimates a 3.08% chance of exploitation in the next 30 days.
Description
CRE Loaded 6.15 allows remote attackers to perform privileged actions, including uploading and creating arbitrary files, via a direct request to files.php. NOTE: the vendor states "The initial announcement of this risk was made on our website... and it included a patch which will close the vulnerability on all known 6.0x and 6.1x releases. We strongly encourage users of CRE Loaded 6.x, osCMax, and other users of osCommerce who have installed HTMLArea based WYSIWYG editors and Admin Access with Levels to modify thier installations at the earliest possible moment."
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cre Loaded | Cre Loaded | 6.15 |
References
- http://secunia.com/advisories/18648Patch, Vendor Advisory
- http://secunia.com/advisories/18648Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2006-0478?
How severe is CVE-2006-0478?
How do I fix CVE-2006-0478?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2006
- CVE-2006-0472Cross-site scripting (XSS) vulnerability in guestbook.php in…
- CVE-2006-0473Cross-site scripting (XSS) vulnerability in the bbcode funct…
- CVE-2006-0474Multiple integer overflows in Shareaza 2.2.1.0 allow remote …
- CVE-2006-0475PHP-Ping 1.3 does not properly validate ping counts, which a…
- CVE-2006-0476Buffer overflow in Nullsoft Winamp 5.12 allows remote attack…
- CVE-2006-0477Buffer overflow in git-checkout-index in GIT before 1.1.5 al…
- CVE-2006-0479pmwiki.php in PmWiki 2.1 beta 20, with register_globals enab…
- CVE-2006-0480Cross-site scripting (XSS) vulnerability in the Articles mod…
- CVE-2006-0481Heap-based buffer overflow in the alpha strip capability in …
- CVE-2006-0482Linux kernel 2.6.15.1 and earlier, when running on SPARC arc…
- CVE-2006-0483Cisco VPN 3000 series concentrators running software 4.7.0 t…
- CVE-2006-0484Directory traversal vulnerability in Vis.pl, as part of the …
Are you affected by CVE-2006-0478?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
