DeluxeBB 1.06 and earlier, when run on the Apache HTTP Server with the mod_mime module, allows remote attackers to execute arbitrary PHP code by uploading files with double extensions via the fileupload parameter in a newthread action in newpost.php.
References
Configurations
Information
Published : 2006-09-06 00:04
Updated : 2017-07-20 01:33
NVD link : CVE-2006-4558
Mitre link : CVE-2006-4558
JSON object : View
Products Affected
deluxebb
- deluxebb
CWE
