The Gallery module in Simone Vellei Flatnuke 2.5.7 and earlier, when Gallery uploads are enabled, does not restrict the extensions of uploaded files that begin with a GIF header, which allows remote authenticated users to execute arbitrary PHP code via an uploaded .php file.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Flatnuke | Flatnuke | * | 2.5.7 (including) |
Flatnuke | Flatnuke | 1.0 (including) | 1.0 (including) |
Flatnuke | Flatnuke | 1.5 (including) | 1.5 (including) |
Flatnuke | Flatnuke | 1.6 (including) | 1.6 (including) |
Flatnuke | Flatnuke | 1.7 (including) | 1.7 (including) |
Flatnuke | Flatnuke | 1.8 (including) | 1.8 (including) |
Flatnuke | Flatnuke | 2.0 (including) | 2.0 (including) |
Flatnuke | Flatnuke | 2.5.1 (including) | 2.5.1 (including) |
Flatnuke | Flatnuke | 2.5.3 (including) | 2.5.3 (including) |
Flatnuke | Flatnuke | 2.5.5 (including) | 2.5.5 (including) |
Flatnuke | Flatnuke | 2.5.6 (including) | 2.5.6 (including) |