Unrestricted file upload vulnerability in imageupload.php in the SimpleBoard (comsimpleboard) component 1.0.1 and earlier for Mambo allows remote attackers to execute arbitrary code by uploading a file with an executable extension and an image/jpeg content type, then accessing this file via a direct request to the file in components/comsimpleboard/, a different vulnerability than CVE-2006-3528.