296,349
Total vulnerabilities in the database
Incomplete blacklist vulnerability in editor/filemanager/upload/php/upload.php in FCKeditor, as used in SiteX CMS 0.7.3.beta, La-Nai CMS, Syntax CMS, Cardinal Cms, and probably other products, allows remote attackers to upload and execute arbitrary PHP code via a file whose name contains ".php." and has an unknown extension, which is recognized as a .php file by the Apache HTTP server, a different vulnerability than CVE-2006-0658 and CVE-2006-2529.
Software | From | Fixed in |
---|---|---|
sitex_cms_project / sitex_cms | 0.7.3-beta | 0.7.3-beta.x |
redlinesoft / lanai_cms | - | 1.2.16.x |
syntax_cms_project / syntax_cms | - | 1.3.x |
cardinal_cms_project / cardinal_cms | 1.2 | 1.2.x |