Vulnerabilities > CVE-2005-2781 - Unspecified vulnerability in Ilia Alshanetsky Fudforum

047910
CVSS 0.0 - NONE
Attack vector
UNKNOWN
Attack complexity
UNKNOWN
Privileges required
UNKNOWN
Confidentiality impact
UNKNOWN
Integrity impact
UNKNOWN
Availability impact
UNKNOWN

Summary

The Avatar upload feature in FUD Forum before 2.7.0 does not properly verify uploaded files, which allows remote attackers to execute arbitrary PHP code via a file with a .php extension that contains image data followed by PHP code.

Nessus

  • NASL familyDebian Local Security Checks
    NASL idDEBIAN_DSA-1063.NASL
    descriptionIt was discovered that the Avatar upload feature of FUD Forum, a component of the web-based groupware system phpgroupware, does not sufficiently validate uploaded files, which might lead to the execution of injected web script code.
    last seen2020-06-01
    modified2020-06-02
    plugin id22605
    published2006-10-14
    reporterThis script is Copyright (C) 2006-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/22605
    titleDebian DSA-1063-1 : phpgroupware - missing input sanitising
  • NASL familyCGI abuses
    NASL idFUDFORUM_AVATAR_UPLOAD.NASL
    descriptionThe remote host is running FUDforum, an open source web forum written in PHP. According to its banner, the version of FUDforum installed on the remote host may allow an authenticated attacker to upload a file with arbitrary PHP code as an avatar image and later run that code subject to the privileges of the web server user id.
    last seen2020-06-01
    modified2020-06-02
    plugin id19520
    published2005-08-29
    reporterThis script is Copyright (C) 2005-2018 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/19520
    titleFUDforum < 2.7.1 Avatar Upload Extension Validation Weakness Arbitrary Code Execution