flatnuke records
22 published records for vendor flatnuke.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 3
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Recurring classes
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-425 Direct Request ('Forced Browsing')1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
22 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
41Plan | CVE-2005-4448No exploit | FlatNuke 2.5.6 verifies authentication credentials based on an MD5 checksum of the admin name and the hashed password rather than the plaintflatnuke · flatnuke | Critical10.0 | — | 2.8% | Dec 21, 2005 |
31Monitor | CVE-2005-1894Proof of concept | Direct code injection vulnerability in FlatNuke 2.5.3 allows remote attackers to execute arbitrary PHP code by placing the code into the Refflatnuke · flatnuke · CWE-94 | High7.5 | — | 3.7% | Jun 9, 2005 |
31Monitor | CVE-2005-0267No exploit | index.php in FlatNuke 2.5.1 allows remote attackers to create an administrator account via carriage returns and #10 in the url_avatar field,flatnuke · flatnuke | High7.5 | — | 1.7% | May 2, 2005 |
30Monitor | CVE-2005-0268No exploit | Direct code injection vulnerability in FlatNuke 2.5.1 allows remote attackers to execute arbitrary PHP code by placing the code into the urlflatnuke · flatnuke | High7.5 | — | 1.5% | Jan 3, 2005 |
26Monitor | CVE-2005-1892No exploit | FlatNuke 2.5.3 allows remote attackers to cause a denial of service or obtain sensitive information via (1) a direct request to foot_news.phflatnuke · flatnuke · CWE-425 | Medium6.4 | — | 2.2% | Jun 9, 2005 |
26Monitor | CVE-2005-2815No exploit | print.php in FlatNuke 2.5.6 allows remote attackers to obtain sensitive information (path disclosure on error) or cause a denial of service flatnuke · flatnuke | Medium6.4 | — | 1.8% | Sep 7, 2005 |
22Monitor | CVE-2005-4208Proof of concept | Directory traversal vulnerability in Flatnuke 2.5.6 allows remote attackers to access arbitrary files via a ..flatnuke · flatnuke | Medium5.0 | — | 8.1% | Dec 13, 2005 |
22Monitor | CVE-2005-2813Proof of concept | Directory traversal vulnerability in FlatNuke 2.5.6 and possibly earlier allows remote attackers to read arbitrary files via ".." sequences flatnuke · flatnuke | Medium5.0 | — | 6.9% | Sep 7, 2005 |
22Monitor | CVE-2005-2540Proof of concept | CRLF injection vulnerability in FlatNuke 2.5.5 and possibly earlier versions allows remote attackers to execute arbitrary PHP commands via aflatnuke · flatnuke | Medium5.0 | — | 6.1% | Aug 10, 2005 |
21Monitor | CVE-2005-3307Proof of concept | Directory traversal vulnerability in index.php for FlatNuke 2.5.6 allows remote attackers to read arbitrary files via ".." sequences in the flatnuke · flatnuke | Medium5.0 | — | 3.1% | Oct 25, 2005 |
21Monitor | CVE-2005-1893Proof of concept | FlatNuke 2.5.3 allows remote attackers to obtain sensitive information via invalid parameters to certain scripts, which leaks the web documeflatnuke · flatnuke | Medium5.0 | — | 2.9% | Jun 9, 2005 |
21Monitor | CVE-2005-1896No exploit | Directory traversal vulnerability in thumb.php in FlatNuke 2.5.3 allows remote attackers to read arbitrary images or obtain the installationflatnuke · flatnuke | Medium5.0 | — | 2.0% | Jun 9, 2005 |
20Monitor | CVE-2005-2538No exploit | FlatNuke 2.5.5 and possibly earlier versions allows remote attackers to obtain sensitive information via (1) a null byte or (2) an MS-DOS deflatnuke · flatnuke | Medium5.0 | — | 1.5% | Aug 10, 2005 |
20Monitor | CVE-2005-2537No exploit | FlatNuke 2.5.5 and possibly earlier versions allows remote attackers to obtain sensitive information via a direct request to structure.php.flatnuke · flatnuke | Medium5.0 | — | 1.5% | Aug 10, 2005 |
19Monitor | CVE-2006-3608Proof of concept | The Gallery module in Simone Vellei Flatnuke 2.5.7 and earlier, when Gallery uploads are enabled, does not restrict the extensions of uploadflatnuke · flatnuke | Medium4.6 | — | 2.3% | Jul 18, 2006 |
18Monitor | CVE-2005-2539Proof of concept | Multiple cross-site scripting (XSS) vulnerabilities in FlatNuke 2.5.5 and possibly earlier versions allow remote attackers to inject arbitraflatnuke · flatnuke | Medium4.3 | — | 2.5% | Aug 10, 2005 |
18Monitor | CVE-2005-1895Proof of concept | Cross-site scripting (XSS) vulnerability in FlatNuke 2.5.3 allows remote attackers to inject arbitrary web script or HTML via the border or flatnuke · flatnuke | Medium4.3 | — | 1.8% | Jun 9, 2005 |
18Monitor | CVE-2005-2814Proof of concept | Cross-site scripting (XSS) vulnerability in FlatNuke 2.5.6 allows remote attackers to inject arbitrary web script or HTML via the usr parameflatnuke · flatnuke | Medium4.3 | — | 1.7% | Sep 7, 2005 |
17Monitor | CVE-2005-4449Proof of concept | verify.php in FlatNuke 2.5.6 allows remote authenticated administrators to modify arbitrary PHP files by setting the file parameter to an arflatnuke · flatnuke | Medium4.0 | — | 4.6% | Dec 21, 2005 |
17Monitor | CVE-2005-3306No exploit | Cross-site scripting (XSS) vulnerability in index.php for FlatNuke 2.5.6 allows remote attackers to inject arbitrary web script or HTML via flatnuke · flatnuke | Medium4.3 | — | 1.2% | Oct 25, 2005 |
17Monitor | CVE-2005-3361No exploit | Cross-site scripting (XSS) vulnerability in forum/index.php in FlatNuke 2.5.6 allows remote attackers to inject arbitrary web script or HTMLflatnuke · flatnuke | Medium4.3 | — | 1.2% | Oct 27, 2005 |
17Monitor | CVE-2007-5109No exploit | Cross-site request forgery (CSRF) vulnerability in index.php in FlatNuke 2.6, and possibly 3, allows remote attackers to change the passwordflatnuke · flatnuke · CWE-352 | Medium4.3 | — | 0.6% | Sep 26, 2007 |
- CVE-2005-444841Plan
FlatNuke 2.5.6 verifies authentication credentials based on an MD5 checksum of the admin name and the hashed password rather than the plaint
CriticalCVSS 10.0No exploitEPSS 3%flatnuke · flatnukeDec 21, 2005
- CVE-2005-189431Monitor
Direct code injection vulnerability in FlatNuke 2.5.3 allows remote attackers to execute arbitrary PHP code by placing the code into the Ref
HighCVSS 7.5Proof of conceptEPSS 4%flatnuke · flatnukeJun 9, 2005
- CVE-2005-026731Monitor
index.php in FlatNuke 2.5.1 allows remote attackers to create an administrator account via carriage returns and #10 in the url_avatar field,
HighCVSS 7.5No exploitEPSS 2%flatnuke · flatnukeMay 2, 2005
- CVE-2005-026830Monitor
Direct code injection vulnerability in FlatNuke 2.5.1 allows remote attackers to execute arbitrary PHP code by placing the code into the url
HighCVSS 7.5No exploitEPSS 2%flatnuke · flatnukeJan 3, 2005
- CVE-2005-189226Monitor
FlatNuke 2.5.3 allows remote attackers to cause a denial of service or obtain sensitive information via (1) a direct request to foot_news.ph
MediumCVSS 6.4No exploitEPSS 2%flatnuke · flatnukeJun 9, 2005
- CVE-2005-281526Monitor
print.php in FlatNuke 2.5.6 allows remote attackers to obtain sensitive information (path disclosure on error) or cause a denial of service
MediumCVSS 6.4No exploitEPSS 2%flatnuke · flatnukeSep 7, 2005
- CVE-2005-420822Monitor
Directory traversal vulnerability in Flatnuke 2.5.6 allows remote attackers to access arbitrary files via a ..
MediumCVSS 5.0Proof of conceptEPSS 8%flatnuke · flatnukeDec 13, 2005
- CVE-2005-281322Monitor
Directory traversal vulnerability in FlatNuke 2.5.6 and possibly earlier allows remote attackers to read arbitrary files via ".." sequences
MediumCVSS 5.0Proof of conceptEPSS 7%flatnuke · flatnukeSep 7, 2005
- CVE-2005-254022Monitor
CRLF injection vulnerability in FlatNuke 2.5.5 and possibly earlier versions allows remote attackers to execute arbitrary PHP commands via a
MediumCVSS 5.0Proof of conceptEPSS 6%flatnuke · flatnukeAug 10, 2005
- CVE-2005-330721Monitor
Directory traversal vulnerability in index.php for FlatNuke 2.5.6 allows remote attackers to read arbitrary files via ".." sequences in the
MediumCVSS 5.0Proof of conceptEPSS 3%flatnuke · flatnukeOct 25, 2005
- CVE-2005-189321Monitor
FlatNuke 2.5.3 allows remote attackers to obtain sensitive information via invalid parameters to certain scripts, which leaks the web docume
MediumCVSS 5.0Proof of conceptEPSS 3%flatnuke · flatnukeJun 9, 2005
- CVE-2005-189621Monitor
Directory traversal vulnerability in thumb.php in FlatNuke 2.5.3 allows remote attackers to read arbitrary images or obtain the installation
MediumCVSS 5.0No exploitEPSS 2%flatnuke · flatnukeJun 9, 2005
- CVE-2005-253820Monitor
FlatNuke 2.5.5 and possibly earlier versions allows remote attackers to obtain sensitive information via (1) a null byte or (2) an MS-DOS de
MediumCVSS 5.0No exploitEPSS 2%flatnuke · flatnukeAug 10, 2005
- CVE-2005-253720Monitor
FlatNuke 2.5.5 and possibly earlier versions allows remote attackers to obtain sensitive information via a direct request to structure.php.
MediumCVSS 5.0No exploitEPSS 2%flatnuke · flatnukeAug 10, 2005
- CVE-2006-360819Monitor
The Gallery module in Simone Vellei Flatnuke 2.5.7 and earlier, when Gallery uploads are enabled, does not restrict the extensions of upload
MediumCVSS 4.6Proof of conceptEPSS 2%flatnuke · flatnukeJul 18, 2006
- CVE-2005-253918Monitor
Multiple cross-site scripting (XSS) vulnerabilities in FlatNuke 2.5.5 and possibly earlier versions allow remote attackers to inject arbitra
MediumCVSS 4.3Proof of conceptEPSS 3%flatnuke · flatnukeAug 10, 2005
- CVE-2005-189518Monitor
Cross-site scripting (XSS) vulnerability in FlatNuke 2.5.3 allows remote attackers to inject arbitrary web script or HTML via the border or
MediumCVSS 4.3Proof of conceptEPSS 2%flatnuke · flatnukeJun 9, 2005
- CVE-2005-281418Monitor
Cross-site scripting (XSS) vulnerability in FlatNuke 2.5.6 allows remote attackers to inject arbitrary web script or HTML via the usr parame
MediumCVSS 4.3Proof of conceptEPSS 2%flatnuke · flatnukeSep 7, 2005
- CVE-2005-444917Monitor
verify.php in FlatNuke 2.5.6 allows remote authenticated administrators to modify arbitrary PHP files by setting the file parameter to an ar
MediumCVSS 4.0Proof of conceptEPSS 5%flatnuke · flatnukeDec 21, 2005
- CVE-2005-330617Monitor
Cross-site scripting (XSS) vulnerability in index.php for FlatNuke 2.5.6 allows remote attackers to inject arbitrary web script or HTML via
MediumCVSS 4.3No exploitEPSS 1%flatnuke · flatnukeOct 25, 2005
- CVE-2005-336117Monitor
Cross-site scripting (XSS) vulnerability in forum/index.php in FlatNuke 2.5.6 allows remote attackers to inject arbitrary web script or HTML
MediumCVSS 4.3No exploitEPSS 1%flatnuke · flatnukeOct 27, 2005
- CVE-2007-510917Monitor
Cross-site request forgery (CSRF) vulnerability in index.php in FlatNuke 2.6, and possibly 3, allows remote attackers to change the password
MediumCVSS 4.3No exploitEPSS 1%flatnuke · flatnukeSep 26, 2007