phpMyFAQ 1.4.0 allows remote attackers to access the Image Manager to upload or delete images without authorization via a direct request.
https://exchange.xforce.ibmcloud.com/vulnerabilities/16814
http://www.securityfocus.com/bid/10813
http://www.phpmyfaq.de/advisory_2004-07-27.php