phpFK - PHP Forum Script ohne MySQL "upload.php" Arbitrary File Upload

21 July 2010
Bookmark and Share
phpFK - PHP Forum Script ohne MySQL is a PHP-based online forum application. The application is exposed to an issue that lets attackers upload arbitrary files because it fails to adequately validate file extensions and content type in the "upload.php" script before uploading them onto the web server.

Ref: http://www.securityfocus.com/bid/41440

10.29.98 - CVE: Not Available
Platform: Web Application