CVE-2006-3362
Last modified
CVE-2006-3362 is a vulnerability of currently unknown severity. Unrestricted file upload vulnerability in connectors/php/connector.php in FCKeditor mcpuk file manager, as used in (1) Geeklog 1.4.0 through 1.4.0sr3, (2) toendaCMS 1.0.0 Shizouka Stable and earlier, (3) WeBid 0.5.4, and possibly other products, when installed on Apache with mod_mime, allows remote attackers to upload and execute arbitrary PHP code via a filename with a .php extension and a trailing extension that is allowed, such as .zip.. EPSS estimates a 4.97% chance of exploitation in the next 30 days.
Description
Unrestricted file upload vulnerability in connectors/php/connector.php in FCKeditor mcpuk file manager, as used in (1) Geeklog 1.4.0 through 1.4.0sr3, (2) toendaCMS 1.0.0 Shizouka Stable and earlier, (3) WeBid 0.5.4, and possibly other products, when installed on Apache with mod_mime, allows remote attackers to upload and execute arbitrary PHP code via a filename with a .php extension and a trailing extension that is allowed, such as .zip.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Geeklog | Geeklog | 1.4.0 |
| Geeklog | Geeklog | 1.4.0_sr1 |
| Geeklog | Geeklog | 1.4.0_sr2 |
| Geeklog | Geeklog | 1.4.0_sr3 |
| Toenda Software Development | Toendacms | 0.6.1 |
| Toenda Software Development | Toendacms | 0.6.2 |
| Toenda Software Development | Toendacms | 0.7 |
| Toenda Software Development | Toendacms | 1.0 |
References
- http://secunia.com/advisories/20886Patch, Vendor Advisory
- http://secunia.com/advisories/21117Vendor Advisory
- http://secunia.com/advisories/20886Patch, Vendor Advisory
- http://secunia.com/advisories/21117Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2006-3362?
How severe is CVE-2006-3362?
How do I fix CVE-2006-3362?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2006
- CVE-2006-3356The TIFFFetchAnyArray function in ImageIO in Apple OS X 10.4…
- CVE-2006-3357Heap-based buffer overflow in HTML Help ActiveX control (hhc…
- CVE-2006-3358Multiple cross-site scripting (XSS) vulnerabilities in index…
- CVE-2006-3359Multiple SQL injection vulnerabilities in index.php in NewsP…
- CVE-2006-3360Directory traversal vulnerability in index.php in phpSysInfo…
- CVE-2006-3361PHP remote file inclusion vulnerability in Stud.IP 1.3.0-2 a…
- CVE-2006-3363PHP remote file inclusion vulnerability in index.php in the …
- CVE-2006-3364SQL injection vulnerability in index.php in the NP_SEO plugi…
- CVE-2006-3365V3 Chat allows remote attackers to obtain the installation p…
- CVE-2006-3366Multiple cross-site scripting (XSS) vulnerabilities in V3 Ch…
- CVE-2006-3367Mp3 JudeBox Server (Mp3NetBox) Beta 1 stores config.inc unde…
- CVE-2006-3368Efone 20000723 stores config.inc under the web document root…
Are you affected by CVE-2006-3362?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
