Vulnerability Description
Free Host Shop Website Generator 3.3 allows remote authenticated users with administrative privileges to upload and execute arbitrary files via a formname parameter with a filename containing a dangerous file extension and a trailing %00.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Free Host Shop | Website Generator | 3.3 |
References
- http://nsag.ru/vuln/894.html
- http://secunia.com/advisories/19014ExploitVendor Advisory
- http://www.securityfocus.com/archive/1/426077/100/0/threaded
- http://www.securityfocus.com/bid/16823
- http://nsag.ru/vuln/894.html
- http://secunia.com/advisories/19014ExploitVendor Advisory
- http://www.securityfocus.com/archive/1/426077/100/0/threaded
- http://www.securityfocus.com/bid/16823
FAQ
What is CVE-2006-0936?
CVE-2006-0936 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Free Host Shop Website Generator 3.3 allows remote authenticated users with administrative privileges to upload and execute arbitrary files via a formname parameter with a filename containing a danger...
How severe is CVE-2006-0936?
CVE-2006-0936 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2006-0936?
Check the references section above for vendor advisories and patch information. Affected products include: Free Host Shop Website Generator.