Vulnerabilities > CVE-2006-0478 - Unspecified vulnerability in CRE Loaded CRE Loaded 6.15

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
cre-loaded
exploit available

Summary

CRE Loaded 6.15 allows remote attackers to perform privileged actions, including uploading and creating arbitrary files, via a direct request to files.php. NOTE: the vendor states "The initial announcement of this risk was made on our website... and it included a patch which will close the vulnerability on all known 6.0x and 6.1x releases. We strongly encourage users of CRE Loaded 6.x, osCMax, and other users of osCommerce who have installed HTMLArea based WYSIWYG editors and Admin Access with Levels to modify thier installations at the earliest possible moment."

Vulnerable Configurations

Part Description Count
Application
Cre_Loaded
1

Exploit-Db

descriptioncreLoaded <= 6.15 (HTMLAREA) Automated Perl Exploit. CVE-2006-0478. Webapps exploit for php platform
idEDB-ID:1446
last seen2016-01-31
modified2006-01-24
published2006-01-24
reporterkaneda
sourcehttps://www.exploit-db.com/download/1446/
titlecreLoaded <= 6.15 HTMLAREA Automated Perl Exploit