SB2020012738 - Code Injection in FUDForum



SB2020012738 - Code Injection in FUDForum

Published: January 27, 2020 Updated: August 8, 2020

Security Bulletin ID SB2020012738
Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Code Injection (CVE-ID: CVE-2013-2267)

The vulnerability allows a remote privileged user to execute arbitrary code.

PHP Code Injection vulnerability in FUDforum Bulletin Board Software 3.0.4 could allow remote attackers to execute arbitrary code on the system.


Remediation

Install update from vendor's website.