The Gallery module in Simone Vellei Flatnuke 2.5.7 and earlier, when Gallery uploads are enabled, does not restrict the extensions of uploaded files that begin with a GIF header, which allows remote authenticated users to execute arbitrary PHP code via an uploaded .php file.
| Software | From | Fixed in |
|---|---|---|
| flatnuke / flatnuke | 1.0 | 1.0.x |
| flatnuke / flatnuke | - | 2.5.7.x |
| flatnuke / flatnuke | 1.5 | 1.5.x |
| flatnuke / flatnuke | 2.5.6 | 2.5.6.x |
| flatnuke / flatnuke | 2.5.1 | 2.5.1.x |
| flatnuke / flatnuke | 2.5.3 | 2.5.3.x |
| flatnuke / flatnuke | 1.6 | 1.6.x |
| flatnuke / flatnuke | 2.0 | 2.0.x |
| flatnuke / flatnuke | 2.5.5 | 2.5.5.x |
| flatnuke / flatnuke | 1.8 | 1.8.x |
| flatnuke / flatnuke | 1.7 | 1.7.x |