CVE-2006-4558

Deluxebb < 1.06 - Unrestricted File Upload

Title source: rule

Description

DeluxeBB 1.06 and earlier, when run on the Apache HTTP Server with the mod_mime module, allows remote attackers to execute arbitrary PHP code by uploading files with double extensions via the fileupload parameter in a newthread action in newpost.php.

Exploits (1)

exploitdb WORKING POC VERIFIED
by rgod · phpwebappsphp
https://www.exploit-db.com/exploits/1797

Scores

EPSS 0.0902
EPSS Percentile 92.6%

Details

CWE
CWE-434
Status published
Products (1)
deluxebb/deluxebb < 1.06
Published Sep 06, 2006
Tracked Since Feb 18, 2026