Description
Ansilove before 1.03 does not filter uploaded file extensions, which allows remote attackers to execute arbitrary code by uploading arbitrary files with dangerous extensions, then accessing them directly in the upload directory.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2006-0702 | Ansilove before 1.03 does not filter uploaded file extensions, which allows remote attackers to execute arbitrary code by uploading arbitrary files with dangerous extensions, then accessing them directly in the upload directory. |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-07T16:41:29.182Z
Reserved: 2006-02-15T00:00:00.000Z
Link: CVE-2006-0695
No data.
Status : Deferred
Published: 2006-02-15T11:06:00.000
Modified: 2025-04-03T01:03:51.193
Link: CVE-2006-0695
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD