The Gallery module in Simone Vellei Flatnuke 2.5.7 and earlier, when Gallery uploads are enabled, does not restrict the extensions of uploaded files that begin with a GIF header, which allows remote authenticated users to execute arbitrary PHP code via an uploaded .php file.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Flatnuke | Flatnuke | * | 2.5.7 (including) |
| Flatnuke | Flatnuke | 1.0 (including) | 1.0 (including) |
| Flatnuke | Flatnuke | 1.5 (including) | 1.5 (including) |
| Flatnuke | Flatnuke | 1.6 (including) | 1.6 (including) |
| Flatnuke | Flatnuke | 1.7 (including) | 1.7 (including) |
| Flatnuke | Flatnuke | 1.8 (including) | 1.8 (including) |
| Flatnuke | Flatnuke | 2.0 (including) | 2.0 (including) |
| Flatnuke | Flatnuke | 2.5.1 (including) | 2.5.1 (including) |
| Flatnuke | Flatnuke | 2.5.3 (including) | 2.5.3 (including) |
| Flatnuke | Flatnuke | 2.5.5 (including) | 2.5.5 (including) |
| Flatnuke | Flatnuke | 2.5.6 (including) | 2.5.6 (including) |