CVE-2006-3362

Exp

Unrestricted file upload vulnerability in connectors/php/connector.php in FCKeditor mcpuk file manager, as used in (1) Geeklog 1.4.0 through 1.4.0sr3, (2) toendaCMS 1.0.0 Shizouka Stable and earlier, (3) WeBid 0.5.4, and possibly other products, when installed on Apache with mod_mime, allows remote attackers to upload and execute arbitrary PHP code via a filename with a .php extension and a trailing extension that is allowed, such as .zip.

Published: 2006-07-06 Last update: 2026-04-16 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2006-3362 is rated High Exploit Risk (70.3/100): CVSS Medium severity, with high exploitation likelihood (EPSS 15.21%, 94th percentile). Core evidence: 4 public exploit reference(s) are indexed (Exploit-DB). EPSS rose +1.87% over the last day, indicating growing attacker interest. Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Public exploit references (Exploit-DB) for CVE-2006-3362

EDB-ID Source Kind Published Link
1964 exploit_db edb 2006-06-29 Exploit-DB ↗
nvd_ref exploit_tag Exploit-DB ↗
nvd_ref exploit_tag Exploit-DB ↗
nvd_ref exploit_tag Exploit-DB ↗

Exploit prediction scoring system (EPSS) score for CVE-2006-3362

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2025-11-16 13.34% 15.21% +1.87%
2 2025-08-14 14.22% 13.34% -0.88%
3 2025-06-08 14.22%

Full EPSS history (17 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2006-3362

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
5.1 2.0 MEDIUM
AV:N/AC:H/Au:N/C:P/I:P/A:P Click to expand
Access vector (AV:N)
Can be exploited remotely over network reachability.
Access complexity (AC:H)
Exploitation requires uncommon or highly specific conditions.
Authentication (AU:N)
No authentication is required.
Confidentiality impact (C:P)
Partial confidentiality impact.
Integrity impact (I:P)
Partial integrity impact.
Availability impact (A:P)
Partial availability impact.
4.9 6.4 [email protected]

Weakness enumeration for CVE-2006-3362

NVD evaluator notes for CVE-2006-3362

Solution: Upgrade to Geeklog version 1.4.0sr4 : http://www.geeklog.net/filemgmt/index.php?id=727

Affected software / configurations for CVE-2006-3362

Vendor Product Version Raw CPE
geeklog geeklog 1.4.0 cpe:2.3:a:geeklog:geeklog:1.4.0:*:*:*:*:*:*:*
geeklog geeklog 1.4.0_sr1 cpe:2.3:a:geeklog:geeklog:1.4.0_sr1:*:*:*:*:*:*:*
geeklog geeklog 1.4.0_sr2 cpe:2.3:a:geeklog:geeklog:1.4.0_sr2:*:*:*:*:*:*:*
geeklog geeklog 1.4.0_sr3 cpe:2.3:a:geeklog:geeklog:1.4.0_sr3:*:*:*:*:*:*:*
toenda_software_development toendacms 0.6.1 cpe:2.3:a:toenda_software_development:toendacms:0.6.1:*:*:*:*:*:*:*
toenda_software_development toendacms 0.6.2 cpe:2.3:a:toenda_software_development:toendacms:0.6.2:*:*:*:*:*:*:*
toenda_software_development toendacms 0.7 cpe:2.3:a:toenda_software_development:toendacms:0.7:*:*:*:*:*:*:*
toenda_software_development toendacms 1.0 cpe:2.3:a:toenda_software_development:toendacms:1.0:*:*:*:*:*:*:*

References for CVE-2006-3362

URL Tags
http://retrogod.altervista.org/toenda_100_shizouka_xpl.html Exploit
http://secunia.com/advisories/20886 Patch Vendor Advisory
http://secunia.com/advisories/21117 Vendor Advisory
http://www.geeklog.net/article.php/exploit-for-fckeditor-filemanager
http://www.geeklog.net/article.php/geeklog-1.4.0sr4
http://www.securityfocus.com/archive/1/440423/100/0/threaded
http://www.securityfocus.com/bid/18767 Exploit
http://www.securityfocus.com/bid/19072 Exploit
http://www.securityfocus.com/bid/30950
http://www.vupen.com/english/advisories/2006/2611
http://www.vupen.com/english/advisories/2006/2868
https://exchange.xforce.ibmcloud.com/vulnerabilities/27469
https://exchange.xforce.ibmcloud.com/vulnerabilities/27494
https://exchange.xforce.ibmcloud.com/vulnerabilities/27799
https://www.exploit-db.com/exploits/1964
https://www.exploit-db.com/exploits/2035
https://www.exploit-db.com/exploits/6344
cvelogic Threat Intelligence