CVE-2006-0478
Last modified
CVE-2006-0478 is a vulnerability of currently unknown severity. CRE Loaded 6.15 allows remote attackers to perform privileged actions, including uploading and creating arbitrary files, via a direct request to files.php. NOTE: the vendor states "The initial announcement of this risk was made on our website... EPSS estimates a 3.08% chance of exploitation in the next 30 days.
Description
CRE Loaded 6.15 allows remote attackers to perform privileged actions, including uploading and creating arbitrary files, via a direct request to files.php. NOTE: the vendor states "The initial announcement of this risk was made on our website... and it included a patch which will close the vulnerability on all known 6.0x and 6.1x releases. We strongly encourage users of CRE Loaded 6.x, osCMax, and other users of osCommerce who have installed HTMLArea based WYSIWYG editors and Admin Access with Levels to modify thier installations at the earliest possible moment."
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cre Loaded | Cre Loaded | 6.15 |
References
- http://secunia.com/advisories/18648Patch, Vendor Advisory
- http://secunia.com/advisories/18648Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2006-0478?
How severe is CVE-2006-0478?
How do I fix CVE-2006-0478?
Are you affected by CVE-2006-0478?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
