Vulnerabilities > CVE-2006-3608 - Remote File Include vulnerability in FlatNuke

047910
CVSS 4.6 - MEDIUM
Attack vector
NETWORK
Attack complexity
HIGH
Privileges required
SINGLE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
high complexity
flatnuke
exploit available

Summary

The Gallery module in Simone Vellei Flatnuke 2.5.7 and earlier, when Gallery uploads are enabled, does not restrict the extensions of uploaded files that begin with a GIF header, which allows remote authenticated users to execute arbitrary PHP code via an uploaded .php file. Successful exploitation requires that Gallery uploads are enabled.

Exploit-Db

descriptionFlatNuke 2.5.7 Index.php Remote File Include Vulnerability. CVE-2006-3608. Webapps exploit for php platform
idEDB-ID:28216
last seen2016-02-03
modified2006-07-13
published2006-07-13
reporterrgod
sourcehttps://www.exploit-db.com/download/28216/
titleFlatNuke 2.5.7 Index.php Remote File Include Vulnerability