Vulnerabilities > CVE-2006-6338 - Unspecified vulnerability in Devilz Clanportal Devilz Clanportal 1.3.6

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
low complexity
devilz-clanportal

Summary

Unrestricted file upload vulnerability in upload/index.php in deV!L`z Clanportal (DZCP) before 1.3.6.1 allows remote attackers to upload and execute arbitrary .php files by embedding PHP code in a JPEG or GIF file that is uploaded to inc/images/uploads/userpics/.

Vulnerable Configurations

Part Description Count
Application
Devilz_Clanportal
1