Unrated severityNVD Advisory· Published May 22, 2006· Updated Apr 16, 2026
CVE-2006-2530
CVE-2006-2530
Description
avatar_upload.asp in Avatar MOD 1.3 for Snitz Forums 3.4, and possibly other versions, allows remote attackers to bypass file type checks and upload arbitrary files via a null byte in the file name, as discovered by the Codescan product.
Affected products
1- cpe:2.3:a:snitz_communications:avatar_mod:1.3:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- secunia.com/advisories/20148nvdPatchVendor Advisory
- www.codescan.com/Advisories/CodeScanLabs_AvatarMod.htmlnvdExploit
- www.security-assessment.com/Whitepapers/0x00_vs_ASP_File_Uploads.pdfnvd
- www.securityfocus.com/archive/1/434366/100/0/threadednvd
- www.securityfocus.com/bid/18014nvd
- www.vupen.com/english/advisories/2006/1854nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/26546nvd
News mentions
0No linked articles in our index yet.