The Avatar upload feature in FUD Forum before 2.7.0 does not properly verify uploaded files, which allows remote attackers to execute arbitrary PHP code via a file with a .php extension that contains image data followed by PHP code.
https://exchange.xforce.ibmcloud.com/vulnerabilities/22076
http://www.securityfocus.com/bid/14678
http://www.securityfocus.com/archive/1/500406/100/0/threaded
http://www.debian.org/security/2006/dsa-1063
http://secunia.com/advisories/20203
http://secunia.com/advisories/16627/