Skip to content
Noroxi

flatnuke records

22 published records for vendor flatnuke.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
3
With a fix record
0%
Median publish → KEV
No record has entered KEV

Records by year

    Bar: total · dark part: CISA KEV.

    All records

    22 records
    • FlatNuke 2.5.6 verifies authentication credentials based on an MD5 checksum of the admin name and the hashed password rather than the plaint

      CriticalCVSS 10.0No exploitEPSS 3%

      flatnuke · flatnukeDec 21, 2005

    • CVE-2005-1894
      31Monitor

      Direct code injection vulnerability in FlatNuke 2.5.3 allows remote attackers to execute arbitrary PHP code by placing the code into the Ref

      HighCVSS 7.5Proof of conceptEPSS 4%

      flatnuke · flatnukeJun 9, 2005

    • CVE-2005-0267
      31Monitor

      index.php in FlatNuke 2.5.1 allows remote attackers to create an administrator account via carriage returns and #10 in the url_avatar field,

      HighCVSS 7.5No exploitEPSS 2%

      flatnuke · flatnukeMay 2, 2005

    • CVE-2005-0268
      30Monitor

      Direct code injection vulnerability in FlatNuke 2.5.1 allows remote attackers to execute arbitrary PHP code by placing the code into the url

      HighCVSS 7.5No exploitEPSS 2%

      flatnuke · flatnukeJan 3, 2005

    • CVE-2005-1892
      26Monitor

      FlatNuke 2.5.3 allows remote attackers to cause a denial of service or obtain sensitive information via (1) a direct request to foot_news.ph

      MediumCVSS 6.4No exploitEPSS 2%

      flatnuke · flatnukeJun 9, 2005

    • CVE-2005-2815
      26Monitor

      print.php in FlatNuke 2.5.6 allows remote attackers to obtain sensitive information (path disclosure on error) or cause a denial of service

      MediumCVSS 6.4No exploitEPSS 2%

      flatnuke · flatnukeSep 7, 2005

    • CVE-2005-4208
      22Monitor

      Directory traversal vulnerability in Flatnuke 2.5.6 allows remote attackers to access arbitrary files via a ..

      MediumCVSS 5.0Proof of conceptEPSS 8%

      flatnuke · flatnukeDec 13, 2005

    • CVE-2005-2813
      22Monitor

      Directory traversal vulnerability in FlatNuke 2.5.6 and possibly earlier allows remote attackers to read arbitrary files via ".." sequences

      MediumCVSS 5.0Proof of conceptEPSS 7%

      flatnuke · flatnukeSep 7, 2005

    • CVE-2005-2540
      22Monitor

      CRLF injection vulnerability in FlatNuke 2.5.5 and possibly earlier versions allows remote attackers to execute arbitrary PHP commands via a

      MediumCVSS 5.0Proof of conceptEPSS 6%

      flatnuke · flatnukeAug 10, 2005

    • CVE-2005-3307
      21Monitor

      Directory traversal vulnerability in index.php for FlatNuke 2.5.6 allows remote attackers to read arbitrary files via ".." sequences in the

      MediumCVSS 5.0Proof of conceptEPSS 3%

      flatnuke · flatnukeOct 25, 2005

    • CVE-2005-1893
      21Monitor

      FlatNuke 2.5.3 allows remote attackers to obtain sensitive information via invalid parameters to certain scripts, which leaks the web docume

      MediumCVSS 5.0Proof of conceptEPSS 3%

      flatnuke · flatnukeJun 9, 2005

    • CVE-2005-1896
      21Monitor

      Directory traversal vulnerability in thumb.php in FlatNuke 2.5.3 allows remote attackers to read arbitrary images or obtain the installation

      MediumCVSS 5.0No exploitEPSS 2%

      flatnuke · flatnukeJun 9, 2005

    • CVE-2005-2538
      20Monitor

      FlatNuke 2.5.5 and possibly earlier versions allows remote attackers to obtain sensitive information via (1) a null byte or (2) an MS-DOS de

      MediumCVSS 5.0No exploitEPSS 2%

      flatnuke · flatnukeAug 10, 2005

    • CVE-2005-2537
      20Monitor

      FlatNuke 2.5.5 and possibly earlier versions allows remote attackers to obtain sensitive information via a direct request to structure.php.

      MediumCVSS 5.0No exploitEPSS 2%

      flatnuke · flatnukeAug 10, 2005

    • CVE-2006-3608
      19Monitor

      The Gallery module in Simone Vellei Flatnuke 2.5.7 and earlier, when Gallery uploads are enabled, does not restrict the extensions of upload

      MediumCVSS 4.6Proof of conceptEPSS 2%

      flatnuke · flatnukeJul 18, 2006

    • CVE-2005-2539
      18Monitor

      Multiple cross-site scripting (XSS) vulnerabilities in FlatNuke 2.5.5 and possibly earlier versions allow remote attackers to inject arbitra

      MediumCVSS 4.3Proof of conceptEPSS 3%

      flatnuke · flatnukeAug 10, 2005

    • CVE-2005-1895
      18Monitor

      Cross-site scripting (XSS) vulnerability in FlatNuke 2.5.3 allows remote attackers to inject arbitrary web script or HTML via the border or

      MediumCVSS 4.3Proof of conceptEPSS 2%

      flatnuke · flatnukeJun 9, 2005

    • CVE-2005-2814
      18Monitor

      Cross-site scripting (XSS) vulnerability in FlatNuke 2.5.6 allows remote attackers to inject arbitrary web script or HTML via the usr parame

      MediumCVSS 4.3Proof of conceptEPSS 2%

      flatnuke · flatnukeSep 7, 2005

    • CVE-2005-4449
      17Monitor

      verify.php in FlatNuke 2.5.6 allows remote authenticated administrators to modify arbitrary PHP files by setting the file parameter to an ar

      MediumCVSS 4.0Proof of conceptEPSS 5%

      flatnuke · flatnukeDec 21, 2005

    • CVE-2005-3306
      17Monitor

      Cross-site scripting (XSS) vulnerability in index.php for FlatNuke 2.5.6 allows remote attackers to inject arbitrary web script or HTML via

      MediumCVSS 4.3No exploitEPSS 1%

      flatnuke · flatnukeOct 25, 2005

    • CVE-2005-3361
      17Monitor

      Cross-site scripting (XSS) vulnerability in forum/index.php in FlatNuke 2.5.6 allows remote attackers to inject arbitrary web script or HTML

      MediumCVSS 4.3No exploitEPSS 1%

      flatnuke · flatnukeOct 27, 2005

    • CVE-2007-5109
      17Monitor

      Cross-site request forgery (CSRF) vulnerability in index.php in FlatNuke 2.6, and possibly 3, allows remote attackers to change the password

      MediumCVSS 4.3No exploitEPSS 1%

      flatnuke · flatnukeSep 26, 2007