CVE-2005-2781
Publication date 2 September 2005
Last updated 17 July 2025
Ubuntu priority
Description
The Avatar upload feature in FUD Forum before 2.7.0 does not properly verify uploaded files, which allows remote attackers to execute arbitrary PHP code via a file with a .php extension that contains image data followed by PHP code.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| egroupware | ||
| phpgroupware | ||