Unrated severityNVD Advisory· Published Jun 19, 2006· Updated Apr 16, 2026
CVE-2006-3070
CVE-2006-3070
Description
write_ok.php in Zeroboard 4.1 pl8, when installed on Apache with mod_mime, allows remote attackers to bypass restrictions for uploading files with executable extensions by uploading a .htaccess file that with an AddType directive that assigns an executable module to files with assumed-safe extensions, as demonstrated by assigning the txt extension to be handled by application/x-httpd-php.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- securecast.wins21.com/zerovul.htmlnvdExploitPatchVendor Advisory
- secunia.com/advisories/20592nvdVendor Advisory
- marc.infonvd
- www.securityfocus.com/archive/1/437442/30/4320/threadednvd
- www.securityfocus.com/bid/18465nvd
- www.vupen.com/english/advisories/2006/2318nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/27038nvd
News mentions
0No linked articles in our index yet.