PunBB 1.2.12 does not properly handle an avatar directory pathname ending in %00, which allows remote authenticated administrative users to upload arbitrary files and execute code, as demonstrated by a query to admin_options.php with an avatars_dir parameter ending in %00. NOTE: this issue was originally disputed by the vendor, but the dispute was withdrawn on 20060926.
References
Configurations
History
21 Nov 2024, 00:16
Type | Values Removed | Values Added |
---|---|---|
References | () http://forums.punbb.org/viewtopic.php?id=13255 - | |
References | () http://www.attrition.org/pipermail/vim/2006-September/001041.html - | |
References | () http://www.attrition.org/pipermail/vim/2006-September/001052.html - | |
References | () http://www.attrition.org/pipermail/vim/2006-September/001055.html - | |
References | () http://www.security.nnov.ru/Odocument221.html - Exploit | |
References | () http://www.securityfocus.com/archive/1/445788/100/0/threaded - | |
References | () http://www.securityfocus.com/archive/1/446420/100/0/threaded - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/28884 - |
Information
Published : 2006-09-13 23:07
Updated : 2024-11-21 00:16
NVD link : CVE-2006-4759
Mitre link : CVE-2006-4759
CVE.ORG link : CVE-2006-4759
JSON object : View
Products Affected
punbb
- punbb
CWE