VYPR
Unrated severityNVD Advisory· Published Feb 28, 2006· Updated Apr 16, 2026

CVE-2006-0936

CVE-2006-0936

Description

Free Host Shop Website Generator 3.3 allows remote authenticated users with administrative privileges to upload and execute arbitrary files via a formname parameter with a filename containing a dangerous file extension and a trailing %00.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.