CVE-2006-3381

SturGeoN Upload - RCE

Title source: llm
STIX 2.1

Description

SturGeoN Upload allows remote attackers to execute arbitrary PHP code by uploading a file with a .php extension, then directly accessing the file. NOTE: It is uncertain whether this is a vulnerability or a feature of the product.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Jihad BENABRA · perlwebappsphp
https://www.exploit-db.com/exploits/28143

Scores

EPSS 0.0317
EPSS Percentile 87.0%

Details

Status published
Products (1)
sturgeon_upload/sturgeon_upload
Published Jul 06, 2006
Tracked Since Feb 18, 2026