Show filters
3 Total Results
Displaying 1-3 of 3
Sort by:
Attacker Value
Unknown

CVE-2006-6360

Disclosure Date: December 07, 2006 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in activate.php in PHP Upload Center 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the footerpage parameter.
0
Attacker Value
Unknown

CVE-2006-1208

Disclosure Date: March 14, 2006 (last updated February 22, 2025)
Sergey Korostel PHP Upload Center allows remote attackers to execute arbitrary PHP code by uploading a file whose name ends in a .php.li extension, which can be accessed from the upload directory.
0
Attacker Value
Unknown

CVE-2006-1207

Disclosure Date: March 14, 2006 (last updated February 22, 2025)
PHP Upload Center stores password hashes under the web root with insufficient access control, which allows remote attackers to download each password hash via a direct request for the upload/users/[USERNAME] file.
0