CVE-2006-2349

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
12/05/2006
Last modified:
03/04/2025

Description

E-Business Designer (eBD) 3.1.4 and earlier allows remote attackers to upload or modify arbitrary files, and execute arbitrary code, via a direct request to (1) common/html_editor/image_browser.upload.html, (2) common/html_editor/image_browser.html, or (3) common/html_editor/html_editor.html. NOTE: this can also be used for cross-site scripting (XSS) attacks by uploading cascading style sheet (.CSS) files.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:oasyssoft:e-business_designer:*:*:*:*:*:*:*:* 3.1.4 (including)