PublicDate: 2005-09-02 23:03:00 UTC Candidate: CVE-2005-2781 References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2781 Description: The Avatar upload feature in FUD Forum before 2.7.0 does not properly verify uploaded files, which allows remote attackers to execute arbitrary PHP code via a file with a .php extension that contains image data followed by PHP code. Ubuntu-Description: Notes: Priority: untriaged Discovered-by: Assigned-to: CVSS: Bugs: dapper_egroupware: released (1.0.0.009.dfsg-3-4) edgy_egroupware: released (1.0.0.009.dfsg-3-4) feisty_egroupware: released (1.0.0.009.dfsg-3-4) devel_egroupware: released (1.0.0.009.dfsg-3-4) dapper_phpgroupware: released (0.9.16.010-1) edgy_phpgroupware: released (0.9.16.010-1) feisty_phpgroupware: released (0.9.16.010-1) devel_phpgroupware: released (0.9.16.010-1) upstream_egroupware: needs-triage upstream_phpgroupware: needs-triage