Vulnerabilities > CVE-2006-2931 - Arbitrary PHP Code Execution vulnerability in CMS Mundo

047910
CVSS 5.1 - MEDIUM
Attack vector
NETWORK
Attack complexity
HIGH
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
high complexity
hotwebscripts

Summary

CMS Mundo before 1.0 build 008 does not properly verify uploaded image files, which allows remote attackers to execute arbitrary PHP code by uploading and later directly accessing certain files.

Vulnerable Configurations

Part Description Count
Application
Hotwebscripts
2