Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The Avatar upload feature in FUD Forum before 2.7.0 does not properly verify uploaded files, which allows remote attackers to execute arbitrary PHP code via a file with a .php extension that contains image data followed by PHP code.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
FUDforum Avatar Upload 任意脚本上传漏洞
Vulnerability Description
FUD Forum是一个基于PHP+MySQL/PostgreSQL构建的开源论坛系统。 FUD Forum 2.7.0以前的版本中的头像上传功能不能正确地验证上传得文件。这使得远程攻击者可借助后缀名为.php的文件执行任意的php代码,其中所述的.php文件包含PHP代码图像数据。
CVSS Information
N/A
Vulnerability Type
N/A