Record summary

CVE-2006-0702 has a selected CVSS score of 5.0; EIP currently links 1 catalogued exploit.

Description

admin/upload.php in imageVue 16.1 allows remote attackers to upload arbitrary files to certain allowed folders via .. (dot dot) sequences in the path parameter. NOTE: due to the lack of details, the specific vulnerability type cannot be determined, although it might be due to directory traversal.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBImageVue 0.16.1 - 'upload.php' Unrestricted Arbitrary File UploadExploitDB exploitby zjiebNot analyzed1 file
ExploitDB

PoC details

References

6