Laurentiu Matei eXpandable Home Page (XHP) CMS 0.5 and earlier allows remote authenticated users to use the HTMLArea FileManager plugin to upload and execute arbitrary PHP files using (1) manager.php, (2) standalonemanager.php, and (3) images.php.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2006-03-23T23:00:00

Updated: 2024-08-07T17:12:20.799Z

Reserved: 2006-03-23T00:00:00

Link: CVE-2006-1371

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2006-03-23T23:06:00.000

Modified: 2017-10-11T01:30:44.843

Link: CVE-2006-1371

cve-icon Redhat

No data.