CVE-2006-0702

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
15/02/2006
Last modified:
20/07/2017

Description

admin/upload.php in imageVue 16.1 allows remote attackers to upload arbitrary files to certain allowed folders via .. (dot dot) sequences in the path parameter. NOTE: due to the lack of details, the specific vulnerability type cannot be determined, although it might be due to directory traversal.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:imagevue:imagevue:0.16.1:*:*:*:*:*:*:*