7.5
CVSSv2

CVE-2005-2781

Published: 02/09/2005 Updated: 19/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The Avatar upload feature in FUD Forum prior to 2.7.0 does not properly verify uploaded files, which allows remote malicious users to execute arbitrary PHP code via a file with a .php extension that contains image data followed by PHP code.

Vulnerable Product Search on Vulmon Subscribe to Product

ilia alshanetsky fudforum 2.2.0

ilia alshanetsky fudforum 2.2.1

ilia alshanetsky fudforum 2.2.2

ilia alshanetsky fudforum 2.3.3

ilia alshanetsky fudforum 2.3.4

ilia alshanetsky fudforum 2.5.2

ilia alshanetsky fudforum 2.6.0

ilia alshanetsky fudforum 2.6.2

ilia alshanetsky fudforum 2.6.3

ilia alshanetsky fudforum 2.7.0

ilia alshanetsky fudforum 2.2.3

ilia alshanetsky fudforum 2.2.4

ilia alshanetsky fudforum 2.3.5

ilia alshanetsky fudforum 2.3.6

ilia alshanetsky fudforum 2.6.1

ilia alshanetsky fudforum 2.6.10

ilia alshanetsky fudforum 2.6.4

ilia alshanetsky fudforum 2.6.5

ilia alshanetsky fudforum 2.1.0

ilia alshanetsky fudforum 2.1.1

ilia alshanetsky fudforum 2.2.5

ilia alshanetsky fudforum 2.3.0

ilia alshanetsky fudforum 2.3.7

ilia alshanetsky fudforum 2.3.8

ilia alshanetsky fudforum 2.6.11

ilia alshanetsky fudforum 2.6.12

ilia alshanetsky fudforum 2.6.6

ilia alshanetsky fudforum 2.6.7

ilia alshanetsky fudforum 2.1.2

ilia alshanetsky fudforum 2.1.3

ilia alshanetsky fudforum 2.3.1

ilia alshanetsky fudforum 2.3.2

ilia alshanetsky fudforum 2.5.0

ilia alshanetsky fudforum 2.5.1

ilia alshanetsky fudforum 2.6.13

ilia alshanetsky fudforum 2.6.14

ilia alshanetsky fudforum 2.6.15

ilia alshanetsky fudforum 2.6.8

ilia alshanetsky fudforum 2.6.9

Vendor Advisories

It was discovered that the Avatar upload feature of FUD Forum, a component of the web based groupware system phpgroupware, does not sufficiently validate uploaded files, which might lead to the execution of injected web script code For the old stable distribution (woody) this problem has been fixed in version 0914-0RC32woody6 For the stable ...