← back
CVE-2006-1668

CVE-2006-1668

23Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendepss 4.1%
exploitation probability
4.1%top 10% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
newimage.php in Eric Gerdes Crafty Syntax Image Gallery (CSIG) (aka PHP thumbnail Photo Gallery) 3.1g and earlier allows remote authenticated users to upload and execute arbitrary PHP code via a multipart/form-data POST with a .jpg filename in the fullimage parameter and the ext parameter set to .php.
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.