peter bassill · operator
$ cve CVE-2006-2330 JSON

CVE-2006-2330 EXPLOIT

6.4
MEDIUM · CVSS 2.0 · EPSS 7.8% (pctl 94)

Patch early

A public exploit exists.

Description

PHP-Fusion 6.00.306 and earlier, running under Apache HTTP Server 1.3.27 and PHP 4.3.3, allows remote authenticated users to upload files of arbitrary types using a filename that contains two or more extensions that ends in an assumed-valid extension such as .gif, which bypasses the validation, as demonstrated by uploading then executing an avatar file that ends in ".php.gif" and contains PHP code in EXIF metadata.

Scoring

CVSS6.4 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
EPSS7.84% — more likely to be exploited than 94% of all CVEs
On CISA KEVno
Public exploityes
Published2006-05-12
Last modified2026-06-16

Affected (1)

VendorProduct
php fusionphp fusion

Public exploits

SourceTitleDate
exploit-dbPHP-Fusion 6.00.306 - Multiple Vulnerabilities2006-05-07

References

→ the Explorer  ·  watch your stack  ·  NVD