AplusWebMaster
Topic Starter
FYI…
- http://secunia.com/advisories/19992/
Release Date: 2006-05-09
Critical: Moderately critical
Impact: System access
Where: From remote
Solution Status: Unpatched… (Ed. note: see update links below)
Software: PHP-Fusion 6.x
…Note: This is only vulnerable on windows systems.
The vulnerabilities have been reported in version 6.00.306. Other versions may also be affected.
Solution:
Edit the source code to ensure that input is properly verified.
Grant only trusted users access to affected systems.
Provided and/or discovered by: rgod …"
- http://www.php-fusion.co.uk/news.php
Critical update - v6.00.307 (May 08 2006)
"…A new exploit has been revealed by rgod. It allows php files to be uploaded as avatars by allowing multiple file extensions. I have addressed this issue and have released updates for v6.00.305 and v6.00.306…"
> http://www.php-fusion.co.uk/downloads.php?cat_id=3
PHP-Fusion 6.00.307 Update for v6.00.306
(Fixes avatar extension exploit.)
PHP-Fusion 6.00.307 Update for v6.00.305
(Fixes potential exploit in forum attachments.
Fixes avatar extension exploit.)

- http://secunia.com/advisories/19992/
Release Date: 2006-05-09
Critical: Moderately critical
Impact: System access
Where: From remote
Solution Status: Unpatched… (Ed. note: see update links below)
Software: PHP-Fusion 6.x
…Note: This is only vulnerable on windows systems.
The vulnerabilities have been reported in version 6.00.306. Other versions may also be affected.
Solution:
Edit the source code to ensure that input is properly verified.
Grant only trusted users access to affected systems.
Provided and/or discovered by: rgod …"
- http://www.php-fusion.co.uk/news.php
Critical update - v6.00.307 (May 08 2006)
"…A new exploit has been revealed by rgod. It allows php files to be uploaded as avatars by allowing multiple file extensions. I have addressed this issue and have released updates for v6.00.305 and v6.00.306…"
> http://www.php-fusion.co.uk/downloads.php?cat_id=3
PHP-Fusion 6.00.307 Update for v6.00.306
(Fixes avatar extension exploit.)
PHP-Fusion 6.00.307 Update for v6.00.305
(Fixes potential exploit in forum attachments.
Fixes avatar extension exploit.)