VulnerabilityModified
CVE-2006-6994
Unrestricted file upload vulnerability in add.asp in OzzyWork Gallery, possibly 2.0 and earlier, allows remote attackers to upload and execute arbitrary ASP files by removing the client-side security checks.
MEDIUM 6.4EPSS 2.24%
Does this matter?
Lower severity and a low EPSS score (2.24%). Track it; it rarely justifies an emergency change on its own.
Description
Unrestricted file upload vulnerability in add.asp in OzzyWork Gallery, possibly 2.0 and earlier, allows remote attackers to upload and execute arbitrary ASP files by removing the client-side security checks.
- CVSS 2.0
- 6.4 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:P
- EPSS
- 2.24% probability · 82th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-434
- Affected
- indirmax.org/ozzywork galeri
- Source
- cve@mitre.org
References
- http://marc.info/?l=bugtraq&m=114723238307299&w=2Third Party Advisory
- http://secunia.com/advisories/20049Broken Link, Permissions Required
- http://www.osvdb.org/25427Broken Link
- http://www.securityfocus.com/bid/17946Broken Link, Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2006/1768Broken Link, Not Applicable
- https://exchange.xforce.ibmcloud.com/vulnerabilities/26365Third Party Advisory, VDB Entry
- http://marc.info/?l=bugtraq&m=114723238307299&w=2Third Party Advisory
- http://secunia.com/advisories/20049Broken Link, Permissions Required
- http://www.osvdb.org/25427Broken Link
- http://www.securityfocus.com/bid/17946Broken Link, Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2006/1768Broken Link, Not Applicable
- https://exchange.xforce.ibmcloud.com/vulnerabilities/26365Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.