CVE-2006-2330

PHP-Fusion 6.00.306- - Authenticated RCE

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2006-2330.

AI-analyzed exploit summary This exploit demonstrates an arbitrary file upload vulnerability in PHPFusion <= v6.00.306, leveraging mod_mime misconfiguration to execute PHP code via malicious avatar uploads, followed by local file inclusion to achieve remote command execution.

Description

PHP-Fusion 6.00.306 and earlier, running under Apache HTTP Server 1.3.27 and PHP 4.3.3, allows remote authenticated users to upload files of arbitrary types using a filename that contains two or more extensions that ends in an assumed-valid extension such as .gif, which bypasses the validation, as demonstrated by uploading then executing an avatar file that ends in ".php.gif" and contains PHP code in EXIF metadata.

Exploits (1)

exploitdb WORKING POC
phpwebappsphp
https://www.exploit-db.com/exploits/1760

This exploit demonstrates an arbitrary file upload vulnerability in PHPFusion <= v6.00.306, leveraging mod_mime misconfiguration to execute PHP code via malicious avatar uploads, followed by local file inclusion to achieve remote command execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: PHPFusion <= v6.00.306
Auth required
Prerequisites: Valid user account for avatar upload · Apache mod_mime misconfiguration · register_globals=on and magic_quotes_gpc=Off
devstral-2 · analyzed Feb 19, 2026 Full analysis →

References (8)

Core 8
Core References
Patch x_refsource_confirm
http://www.php-fusion.co.uk/news.php
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/873
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/26388
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/25537
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/433277/100/0/threaded
Patch, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/19992
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/17898
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/1735

Scores

EPSS 0.1147
EPSS Percentile 93.8%

Details

Status published
Products (11)
php_fusion/php_fusion 6.00.3
php_fusion/php_fusion 6.00.105
php_fusion/php_fusion 6.00.106
php_fusion/php_fusion 6.00.107
php_fusion/php_fusion 6.00.109
php_fusion/php_fusion 6.00.110
php_fusion/php_fusion 6.00.204
php_fusion/php_fusion 6.00.206
php_fusion/php_fusion 6.00.303
php_fusion/php_fusion 6.00.304
... and 1 more
Published May 12, 2006
Tracked Since Feb 18, 2026