CVE-2006-4558

Deluxebb < 1.06 - Unrestricted File Upload

Title source: rule

Description

DeluxeBB 1.06 and earlier, when run on the Apache HTTP Server with the mod_mime module, allows remote attackers to execute arbitrary PHP code by uploading files with double extensions via the fileupload parameter in a newthread action in newpost.php.

Exploits (1)

exploitdb WORKING POC VERIFIED
by rgod · phpwebappsphp
https://www.exploit-db.com/exploits/1797

Scores

EPSS 0.0902
EPSS Percentile 92.5%

Classification

CWE
CWE-434
Status draft

Affected Products (1)

deluxebb/deluxebb < 1.06

Timeline

Published Sep 06, 2006
Tracked Since Feb 18, 2026