CVE-2006-0702
imagevue 16.1 - Unauthenticated Arbitrary File Upload via Path Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-0702. PoCs published by zjieb.
AI-analyzed exploit summary The provided text describes a path traversal vulnerability in ImageVue's upload functionality, allowing unauthorized file uploads to arbitrary directories. It lacks executable code but outlines the steps to exploit the flaw.
Description
admin/upload.php in imageVue 16.1 allows remote attackers to upload arbitrary files to certain allowed folders via .. (dot dot) sequences in the path parameter. NOTE: due to the lack of details, the specific vulnerability type cannot be determined, although it might be due to directory traversal.
Exploits (1)
The provided text describes a path traversal vulnerability in ImageVue's upload functionality, allowing unauthorized file uploads to arbitrary directories. It lacks executable code but outlines the steps to exploit the flaw.