Vulnerability Details CVE-2006-3608
The Gallery module in Simone Vellei Flatnuke 2.5.7 and earlier, when Gallery uploads are enabled, does not restrict the extensions of uploaded files that begin with a GIF header, which allows remote authenticated users to execute arbitrary PHP code via an uploaded .php file.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.036
EPSS Ranking 87.3%
CVSS Severity
CVSS v2 Score 4.6
Products affected by CVE-2006-3608
-
cpe:2.3:a:flatnuke:flatnuke:1.0
-
cpe:2.3:a:flatnuke:flatnuke:1.5
-
cpe:2.3:a:flatnuke:flatnuke:1.6
-
cpe:2.3:a:flatnuke:flatnuke:1.7
-
cpe:2.3:a:flatnuke:flatnuke:1.8
-
cpe:2.3:a:flatnuke:flatnuke:2.0
-
cpe:2.3:a:flatnuke:flatnuke:2.1
-
cpe:2.3:a:flatnuke:flatnuke:2.2
-
cpe:2.3:a:flatnuke:flatnuke:2.3
-
cpe:2.3:a:flatnuke:flatnuke:2.3.1
-
cpe:2.3:a:flatnuke:flatnuke:2.4
-
cpe:2.3:a:flatnuke:flatnuke:2.4.1
-
cpe:2.3:a:flatnuke:flatnuke:2.5
-
cpe:2.3:a:flatnuke:flatnuke:2.5.1
-
cpe:2.3:a:flatnuke:flatnuke:2.5.2
-
cpe:2.3:a:flatnuke:flatnuke:2.5.3
-
cpe:2.3:a:flatnuke:flatnuke:2.5.4
-
cpe:2.3:a:flatnuke:flatnuke:2.5.5
-
cpe:2.3:a:flatnuke:flatnuke:2.5.6
-
cpe:2.3:a:flatnuke:flatnuke:2.5.7