Unrated severityNVD Advisory· Published Jun 21, 2006· Updated Apr 16, 2026
CVE-2006-3128
CVE-2006-3128
Description
choose_file.php in easy-CMS 0.1.2, when mod_mime is installed, does not restrict uploads of filenames with multiple extensions, which allows remote attackers to execute arbitrary PHP code by uploading a PHP file with a GIF file extension, then directly accessing that file in the Repositories directory.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
8- secunia.com/advisories/20733nvdVendor Advisory
- biyosecurity.be/bugs/easycms.txtnvd
- securitytracker.com/idnvd
- www.osvdb.org/26633nvd
- www.securityfocus.com/archive/1/437705/100/0/threadednvd
- www.securityfocus.com/bid/18496nvd
- www.vupen.com/english/advisories/2006/2419nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/27281nvd
News mentions
0No linked articles in our index yet.