avatar_upload.asp in Avatar MOD 1.3 for Snitz Forums 3.4, and possibly other versions, allows remote attackers to bypass file type checks and upload arbitrary files via a null byte in the file name, as discovered by the Codescan product.
2006-05-22T23:10:00.000
2025-04-03T01:03:51.193
Deferred
CVSSv2: 5.0 (MEDIUM)
AV:N/AC:L/Au:N/C:N/I:P/A:N
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | snitz_communications | avatar_mod | 1.3 | Yes |
Application | snitz_communications | snitz_forums_2000 | 3.4.02 | No |
Application | snitz_communications | snitz_forums_2000 | 3.4.03 | No |
Application | snitz_communications | snitz_forums_2000 | 3.4.04 | No |
Application | snitz_communications | snitz_forums_2000 | 3.4.05 | No |
Application | snitz_communications | snitz_forums_2000 | 3.4.06 | No |
Application | snitz_communications | snitz_forums_2000 | 3.4.07 | No |