CVE-2006-4558

Severity CVSS v4.0:
Pending analysis
Type:
CWE-434 Unrestricted Upload of File with Dangerous Type
Publication date:
06/09/2006
Last modified:
03/04/2025

Description

DeluxeBB 1.06 and earlier, when run on the Apache HTTP Server with the mod_mime module, allows remote attackers to execute arbitrary PHP code by uploading files with double extensions via the fileupload parameter in a newthread action in newpost.php.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:deluxebb:deluxebb:*:*:*:*:*:*:*:* 1.06 (including)