Vulnerabilities > CVE-2006-0695 - Input Validation vulnerability in Ansilove 1.01/1.02
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
PARTIAL Integrity impact
PARTIAL Availability impact
PARTIAL Summary
Ansilove before 1.03 does not filter uploaded file extensions, which allows remote attackers to execute arbitrary code by uploading arbitrary files with dangerous extensions, then accessing them directly in the upload directory.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 2 |