images.php in Justin White (aka YTZ) Free Web Publishing System (FreeWPS) 2.11 allows remote attackers to execute arbitrary PHP code by uploading a .php file into the /upload directory as specified in the dirPath parameter, then performing a direct request to that file.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2006-03-23T11:00:00

Updated: 2024-08-07T17:12:20.782Z

Reserved: 2006-03-23T00:00:00

Link: CVE-2006-1363

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2006-03-23T11:06:00.000

Modified: 2025-04-03T01:03:51.193

Link: CVE-2006-1363

cve-icon Redhat

No data.