FlatNuke 2.5.1

CPE Details

FlatNuke 2.5.1
2.5.1
2023-12-28
12h54 +00:00
2023-12-28
12h54 +00:00
Alerte pour un CPE
Restez informé de toutes modifications pour un CPE spécifique.
Gestion des notifications

CPE Name: cpe:2.3:a:flatnuke:flatnuke:2.5.1:*:*:*:*:*:*:*

Informations

Vendor

flatnuke

Product

flatnuke

Version

2.5.1

Related CVE

Open and find in CVE List

CVE ID Publié Description Score Gravité
CVE-2006-3608 2006-07-14 19h00 +00:00 The Gallery module in Simone Vellei Flatnuke 2.5.7 and earlier, when Gallery uploads are enabled, does not restrict the extensions of uploaded files that begin with a GIF header, which allows remote authenticated users to execute arbitrary PHP code via an uploaded .php file.
4.6
CVE-2005-1892 2005-06-08 02h00 +00:00 FlatNuke 2.5.3 allows remote attackers to cause a denial of service or obtain sensitive information via (1) a direct request to foot_news.php, which triggers an infinite loop, or (2) direct requests to unknown scripts, which reveals the web document root in an error message.
6.4
CVE-2005-0267 2005-02-10 04h00 +00:00 index.php in FlatNuke 2.5.1 allows remote attackers to create an administrator account via carriage returns and #10 in the url_avatar field, which is interpreted as a sensitive directive.
7.5
CVE-2005-0268 2005-02-10 04h00 +00:00 Direct code injection vulnerability in FlatNuke 2.5.1 allows remote attackers to execute arbitrary PHP code by placing the code into the url_avatar field.
7.5