CVE-2006-7134 describes an unrestricted file upload vulnerability in main_user.php within Upload Tool for PHP 1.0, allowing remote attackers to upload and execute arbitrary files with executable extensions. This vulnerability carries a critical CVSS score of 10.0, indicating a severe risk with network accessibility, low attack complexity, and complete compromise of confidentiality, integrity, and availability. While no active exploitation is confirmed and there's minimal community discussion or media coverage, an ExploitDB entry (EDB-2791) for an information disclosure vulnerability in a related component suggests potential avenues for further investigation or exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0CPE matchmatch criteria | cpe:2.3:a:noah_spurrier:upload_tool_for_php:1.0:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.