Vulnerabilities > CVE-2005-2781 - Unspecified vulnerability in Ilia Alshanetsky Fudforum

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
ilia-alshanetsky
nessus

Summary

The Avatar upload feature in FUD Forum before 2.7.0 does not properly verify uploaded files, which allows remote attackers to execute arbitrary PHP code via a file with a .php extension that contains image data followed by PHP code.

Nessus

  • NASL familyDebian Local Security Checks
    NASL idDEBIAN_DSA-1063.NASL
    descriptionIt was discovered that the Avatar upload feature of FUD Forum, a component of the web-based groupware system phpgroupware, does not sufficiently validate uploaded files, which might lead to the execution of injected web script code.
    last seen2020-06-01
    modified2020-06-02
    plugin id22605
    published2006-10-14
    reporterThis script is Copyright (C) 2006-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/22605
    titleDebian DSA-1063-1 : phpgroupware - missing input sanitising
  • NASL familyCGI abuses
    NASL idFUDFORUM_AVATAR_UPLOAD.NASL
    descriptionThe remote host is running FUDforum, an open source web forum written in PHP. According to its banner, the version of FUDforum installed on the remote host may allow an authenticated attacker to upload a file with arbitrary PHP code as an avatar image and later run that code subject to the privileges of the web server user id.
    last seen2020-06-01
    modified2020-06-02
    plugin id19520
    published2005-08-29
    reporterThis script is Copyright (C) 2005-2018 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/19520
    titleFUDforum < 2.7.1 Avatar Upload Extension Validation Weakness Arbitrary Code Execution