Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

FUDforum Avatar Upload Arbitrary Script Upload Vulnerability

FUDforum is prone to a remote arbitrary PHP file-upload vulnerability.

An attacker can merge an image file with a script file and upload it to an affected server.

This issue can facilitate unauthorized remote access.

Versions prior to FUDforum 2.7.1 are reported affected. Currently, Symantec cannot confirm if version 2.7.1 is affected as well.







 

Privacy Statement
Copyright 2008, SecurityFocus