CVE-2006-3336
Published Jul 5, 2006
Last updated 14 years ago
Overview
- Description
- TWiki 01-Dec-2000 up to 4.0.3 allows remote attackers to bypass the upload filter and execute arbitrary code via filenames with double extensions such as ".php.en", ".php.1", and other allowed extensions that are not .txt. NOTE: this is only a vulnerability when the server allows script execution in the pub directory.
- Source
- cve@mitre.org
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 4
- Impact score
- 4.9
- Exploitability score
- 4.9
- Vector string
- AV:N/AC:H/Au:N/C:P/I:P/A:N
Weaknesses
- nvd@nist.gov
- NVD-CWE-Other
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:twiki:twiki:4.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A0E0A8F3-02EE-4A6D-BAAC-1D52DF063197" }, { "criteria": "cpe:2.3:a:twiki:twiki:4.0.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F893E121-82FA-41C8-9BA4-606E6DA01408" }, { "criteria": "cpe:2.3:a:twiki:twiki:4.0.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "47807C3A-8430-48E3-A7C8-C5A1FEDF84C0" }, { "criteria": "cpe:2.3:a:twiki:twiki:4.0.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "620356EA-F106-41DF-AADA-C1EF5A5A0829" }, { "criteria": "cpe:2.3:a:twiki:twiki:4.0.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "979D8BC8-0032-496F-9503-F3BBBC8FA7CF" }, { "criteria": "cpe:2.3:a:twiki:twiki:2000-12-01:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "89599BC3-E1D8-4670-9321-F63A788096A0" }, { "criteria": "cpe:2.3:a:twiki:twiki:2001-09-01:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "354C8BA8-603D-4556-8C4C-39DEE4891719" }, { "criteria": "cpe:2.3:a:twiki:twiki:2001-12-01:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "23CC3B43-A77A-471E-A0ED-E91E53C2400C" }, { "criteria": "cpe:2.3:a:twiki:twiki:2003-02-01:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "374ADC0F-0EE2-4DEC-8A37-5F5F15C8137A" }, { "criteria": "cpe:2.3:a:twiki:twiki:2004-09-01:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "BEC5965A-BFC8-42B3-AF13-28E097381E84" }, { "criteria": "cpe:2.3:a:twiki:twiki:2004-09-02:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C94AFFF9-5951-43A9-8018-B10C3F097CE9" }, { "criteria": "cpe:2.3:a:twiki:twiki:2004-09-03:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5F823DF7-B38E-4FBF-8D9A-C1B49FC237BE" }, { "criteria": "cpe:2.3:a:twiki:twiki:2004-09-04:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FFA8E461-0CAA-4B44-8BCC-21CD8E1A6A41" } ], "operator": "OR" } ] } ]