Shodan
Maps
Images
Monitor
Developer
More...
Dashboard
View Api Docs
Vulnerabilities
By Date
Known Exploited
Advanced Search
Vulnerable Software
Vendors
Products
Vulnerability Details CVE-2006-2530
avatar_upload.asp in Avatar MOD 1.3 for Snitz Forums 3.4, and possibly other versions, allows remote attackers to bypass file type checks and upload arbitrary files via a null byte in the file name, as discovered by the Codescan product.
Exploit prediction scoring system (EPSS) score
EPSS Score
0.015
EPSS Ranking
80.3%
CVSS Severity
CVSS v2 Score
5.0
References
http://secunia.com/advisories/20148
http://www.codescan.com/Advisories/CodeScanLabs_AvatarMod.html
http://www.security-assessment.com/Whitepapers/0x00_vs_ASP_File_Uploads.pdf
http://www.securityfocus.com/archive/1/434366/100/0/threaded
http://www.securityfocus.com/bid/18014
http://www.vupen.com/english/advisories/2006/1854
https://exchange.xforce.ibmcloud.com/vulnerabilities/26546
http://secunia.com/advisories/20148
http://www.codescan.com/Advisories/CodeScanLabs_AvatarMod.html
http://www.security-assessment.com/Whitepapers/0x00_vs_ASP_File_Uploads.pdf
http://www.securityfocus.com/archive/1/434366/100/0/threaded
http://www.securityfocus.com/bid/18014
http://www.vupen.com/english/advisories/2006/1854
https://exchange.xforce.ibmcloud.com/vulnerabilities/26546
Products affected by CVE-2006-2530
Snitz Communications
»
Avatar Mod
»
Version:
1.3
cpe:2.3:a:snitz_communications:avatar_mod:1.3
Snitz Communications
»
Snitz Forums 2000
»
Version:
3.4.02
cpe:2.3:a:snitz_communications:snitz_forums_2000:3.4.02
Snitz Communications
»
Snitz Forums 2000
»
Version:
3.4.03
cpe:2.3:a:snitz_communications:snitz_forums_2000:3.4.03
Snitz Communications
»
Snitz Forums 2000
»
Version:
3.4.04
cpe:2.3:a:snitz_communications:snitz_forums_2000:3.4.04
Snitz Communications
»
Snitz Forums 2000
»
Version:
3.4.05
cpe:2.3:a:snitz_communications:snitz_forums_2000:3.4.05
Snitz Communications
»
Snitz Forums 2000
»
Version:
3.4.06
cpe:2.3:a:snitz_communications:snitz_forums_2000:3.4.06
Snitz Communications
»
Snitz Forums 2000
»
Version:
3.4.07
cpe:2.3:a:snitz_communications:snitz_forums_2000:3.4.07
Products
Monitor
Search Engine
Developer API
Maps
Bulk Data
Images
Snippets
Pricing
Membership
API Subscriptions
Enterprise
Contact Us
support@shodan.io
Shodan ® - All rights reserved