Unrated severityNVD Advisory· Published Mar 2, 2007· Updated Apr 23, 2026
CVE-2006-7070
CVE-2006-7070
Description
Unrestricted file upload vulnerability in manager/media/ibrowser/scripts/rfiles.php in Etomite CMS 0.6.1 and earlier allows remote attackers to upload and execute arbitrary files via an nfile[] parameter with a filename that contains a .php extension followed by a valid image extension such as .gif or .jpg, then calling the rename function.
Affected products
2Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
10- secunia.com/advisories/21208nvdPatchVendor Advisory
- www.etomite.org/forums/index.phpnvdPatch
- retrogod.altervista.org/etomite_061_cmd.htmlnvdExploit
- www.securityfocus.com/bid/19157nvdExploitVendor Advisory
- securitytracker.com/idnvdVendor Advisory
- securityreason.com/securityalert/2326nvd
- www.osvdb.org/27543nvd
- www.securityfocus.com/archive/1/441202/100/0/threadednvd
- exchange.xforce.ibmcloud.com/vulnerabilities/27947nvd
- www.exploit-db.com/exploits/2072nvd
News mentions
0No linked articles in our index yet.