CVE
- Id
- 13987
- CVE No.
- CVE-2005-2781
- Status
- Candidate
- Description
- The Avatar upload feature in FUD Forum before 2.7.0 does not properly verify uploaded files, which allows remote attackers to execute arbitrary PHP code via a file with a .php extension that contains image data followed by PHP code.
- Phase
- Assigned (20050902)
- Votes
- None (candidate not yet proposed)
- Comments