18648Third-party advisory
http://secunia.com/advisories/18648 CVE-2006-0478
creLoaded 6.15 - 'HTMLAREA' Automated Perl
Record summary
CVE-2006-0478 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.
Description
CRE Loaded 6.15 allows remote attackers to perform privileged actions, including uploading and creating arbitrary files, via a direct request to files.php. NOTE: the vendor states "The initial announcement of this risk was made on our website... and it included a patch which will close the vulnerability on all known 6.0x and 6.1x releases. We strongly encourage users of CRE Loaded 6.x, osCMax, and other users of osCommerce who have installed HTMLArea based WYSIWYG editors and Admin Access with Levels to modify thier installations at the earliest possible moment."
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBcreLoaded 6.15 - 'HTMLAREA' Automated PerlExploitDB exploitby kanedaNot analyzed1 file
References
720060203 vendor ack/fix: 22793: CRE Loaded files.php Unauthenticated Arbitrary File Upload (fwd)mailing list
http://www.attrition.org/pipermail/vim/2006-February/000527.html 22793vdb entry
http://www.osvdb.org/22793 16415vdb entry
http://www.securityfocus.com/bid/16415 ADV-2006-0373vdb entry
http://www.vupen.com/english/advisories/2006/0373 creloaded-files-auth-bypass(24377)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/24377 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2006-0478