The file extension check in GNUBoard 3.40 and earlier only verifies extensions that contain all lowercase letters, which allows remote attackers to upload arbitrary files via file extensions that include uppercase letters.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2005-02-10T05:00:00

Updated: 2024-08-07T21:05:25.404Z

Reserved: 2005-02-10T00:00:00

Link: CVE-2005-0269

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2005-05-02T04:00:00.000

Modified: 2024-02-02T02:15:17.823

Link: CVE-2005-0269

cve-icon Redhat

No data.