DeluxeBB 1.06 and earlier, when run on the Apache HTTP Server with the mod_mime module, allows remote attackers to execute arbitrary PHP code by uploading files with double extensions via the fileupload parameter in a newthread action in newpost.php.
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Link | Tags |
---|---|
http://securityreason.com/securityalert/1492 | third party advisory exploit |
http://retrogod.altervista.org/deluxebb_106_xpl.html | broken link exploit |
http://www.vupen.com/english/advisories/2006/1843 | vdb entry broken link |
https://exchange.xforce.ibmcloud.com/vulnerabilities/26485 | vdb entry third party advisory |
http://secunia.com/advisories/20135 | broken link third party advisory patch vendor advisory |
http://archives.neohapsis.com/archives/bugtraq/2006-05/0318.html | mailing list exploit broken link |