Vulnerabilities > CVE-2005-2781 - Unspecified vulnerability in Ilia Alshanetsky Fudforum
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN ilia-alshanetsky
nessus
Summary
The Avatar upload feature in FUD Forum before 2.7.0 does not properly verify uploaded files, which allows remote attackers to execute arbitrary PHP code via a file with a .php extension that contains image data followed by PHP code.
Vulnerable Configurations
Nessus
NASL family Debian Local Security Checks NASL id DEBIAN_DSA-1063.NASL description It was discovered that the Avatar upload feature of FUD Forum, a component of the web-based groupware system phpgroupware, does not sufficiently validate uploaded files, which might lead to the execution of injected web script code. last seen 2020-06-01 modified 2020-06-02 plugin id 22605 published 2006-10-14 reporter This script is Copyright (C) 2006-2019 Tenable Network Security, Inc. source https://www.tenable.com/plugins/nessus/22605 title Debian DSA-1063-1 : phpgroupware - missing input sanitising NASL family CGI abuses NASL id FUDFORUM_AVATAR_UPLOAD.NASL description The remote host is running FUDforum, an open source web forum written in PHP. According to its banner, the version of FUDforum installed on the remote host may allow an authenticated attacker to upload a file with arbitrary PHP code as an avatar image and later run that code subject to the privileges of the web server user id. last seen 2020-06-01 modified 2020-06-02 plugin id 19520 published 2005-08-29 reporter This script is Copyright (C) 2005-2018 Tenable Network Security, Inc. source https://www.tenable.com/plugins/nessus/19520 title FUDforum < 2.7.1 Avatar Upload Extension Validation Weakness Arbitrary Code Execution
References
- http://fudforum.org/forum/index.php?t=msg&th=5470&start=0&
- http://fudforum.org/forum/index.php?t=msg&th=5470&start=0&
- http://marc.info/?l=bugtraq&m=112534235403406&w=2
- http://marc.info/?l=bugtraq&m=112534235403406&w=2
- http://secunia.com/advisories/16627/
- http://secunia.com/advisories/16627/
- http://secunia.com/advisories/20203
- http://secunia.com/advisories/20203
- http://www.debian.org/security/2006/dsa-1063
- http://www.debian.org/security/2006/dsa-1063
- http://www.securityfocus.com/archive/1/500406/100/0/threaded
- http://www.securityfocus.com/archive/1/500406/100/0/threaded
- http://www.securityfocus.com/bid/14678
- http://www.securityfocus.com/bid/14678
- https://exchange.xforce.ibmcloud.com/vulnerabilities/22076
- https://exchange.xforce.ibmcloud.com/vulnerabilities/22076