VYPR
Unrated severityNVD Advisory· Published Jul 6, 2006· Updated Apr 16, 2026

CVE-2006-3362

CVE-2006-3362

Description

Unrestricted file upload vulnerability in connectors/php/connector.php in FCKeditor mcpuk file manager, as used in (1) Geeklog 1.4.0 through 1.4.0sr3, (2) toendaCMS 1.0.0 Shizouka Stable and earlier, (3) WeBid 0.5.4, and possibly other products, when installed on Apache with mod_mime, allows remote attackers to upload and execute arbitrary PHP code via a filename with a .php extension and a trailing extension that is allowed, such as .zip.

Affected products

8
  • Geeklog/Geeklog4 versions
    cpe:2.3:a:geeklog:geeklog:1.4.0:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:a:geeklog:geeklog:1.4.0:*:*:*:*:*:*:*
    • cpe:2.3:a:geeklog:geeklog:1.4.0_sr1:*:*:*:*:*:*:*
    • cpe:2.3:a:geeklog:geeklog:1.4.0_sr2:*:*:*:*:*:*:*
    • cpe:2.3:a:geeklog:geeklog:1.4.0_sr3:*:*:*:*:*:*:*
  • cpe:2.3:a:toenda_software_development:toendacms:0.6.1:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:a:toenda_software_development:toendacms:0.6.1:*:*:*:*:*:*:*
    • cpe:2.3:a:toenda_software_development:toendacms:0.6.2:*:*:*:*:*:*:*
    • cpe:2.3:a:toenda_software_development:toendacms:0.7:*:*:*:*:*:*:*
    • cpe:2.3:a:toenda_software_development:toendacms:1.0:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

17

News mentions

0

No linked articles in our index yet.