Записи flatnuke
22 опубликованных записей вендора flatnuke.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 3
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Записи по годам
Столбик: всего · тёмная часть: CISA KEV.
Повторяющиеся классы
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-425 Direct Request ('Forced Browsing')1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEПрофиль атаки
Все записи
22 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
41В плане | CVE-2005-4448Эксплойта нет | FlatNuke 2.5.6 verifies authentication credentials based on an MD5 checksum of the admin name and the hashed password rather than the plaintflatnuke · flatnuke | Критическая10,0 | — | 2,8 % | 21 дек. 2005 г. |
31Наблюдать | CVE-2005-1894Proof of concept | Direct code injection vulnerability in FlatNuke 2.5.3 allows remote attackers to execute arbitrary PHP code by placing the code into the Refflatnuke · flatnuke · CWE-94 | Высокая7,5 | — | 3,7 % | 9 июн. 2005 г. |
31Наблюдать | CVE-2005-0267Эксплойта нет | index.php in FlatNuke 2.5.1 allows remote attackers to create an administrator account via carriage returns and #10 in the url_avatar field,flatnuke · flatnuke | Высокая7,5 | — | 1,7 % | 2 мая 2005 г. |
30Наблюдать | CVE-2005-0268Эксплойта нет | Direct code injection vulnerability in FlatNuke 2.5.1 allows remote attackers to execute arbitrary PHP code by placing the code into the urlflatnuke · flatnuke | Высокая7,5 | — | 1,5 % | 3 янв. 2005 г. |
26Наблюдать | CVE-2005-1892Эксплойта нет | FlatNuke 2.5.3 allows remote attackers to cause a denial of service or obtain sensitive information via (1) a direct request to foot_news.phflatnuke · flatnuke · CWE-425 | Средняя6,4 | — | 2,2 % | 9 июн. 2005 г. |
26Наблюдать | CVE-2005-2815Эксплойта нет | print.php in FlatNuke 2.5.6 allows remote attackers to obtain sensitive information (path disclosure on error) or cause a denial of service flatnuke · flatnuke | Средняя6,4 | — | 1,8 % | 7 сент. 2005 г. |
22Наблюдать | CVE-2005-4208Proof of concept | Directory traversal vulnerability in Flatnuke 2.5.6 allows remote attackers to access arbitrary files via a ..flatnuke · flatnuke | Средняя5,0 | — | 8,1 % | 13 дек. 2005 г. |
22Наблюдать | CVE-2005-2813Proof of concept | Directory traversal vulnerability in FlatNuke 2.5.6 and possibly earlier allows remote attackers to read arbitrary files via ".." sequences flatnuke · flatnuke | Средняя5,0 | — | 6,9 % | 7 сент. 2005 г. |
22Наблюдать | CVE-2005-2540Proof of concept | CRLF injection vulnerability in FlatNuke 2.5.5 and possibly earlier versions allows remote attackers to execute arbitrary PHP commands via aflatnuke · flatnuke | Средняя5,0 | — | 6,1 % | 10 авг. 2005 г. |
21Наблюдать | CVE-2005-3307Proof of concept | Directory traversal vulnerability in index.php for FlatNuke 2.5.6 allows remote attackers to read arbitrary files via ".." sequences in the flatnuke · flatnuke | Средняя5,0 | — | 3,1 % | 25 окт. 2005 г. |
21Наблюдать | CVE-2005-1893Proof of concept | FlatNuke 2.5.3 allows remote attackers to obtain sensitive information via invalid parameters to certain scripts, which leaks the web documeflatnuke · flatnuke | Средняя5,0 | — | 2,9 % | 9 июн. 2005 г. |
21Наблюдать | CVE-2005-1896Эксплойта нет | Directory traversal vulnerability in thumb.php in FlatNuke 2.5.3 allows remote attackers to read arbitrary images or obtain the installationflatnuke · flatnuke | Средняя5,0 | — | 2,0 % | 9 июн. 2005 г. |
20Наблюдать | CVE-2005-2538Эксплойта нет | FlatNuke 2.5.5 and possibly earlier versions allows remote attackers to obtain sensitive information via (1) a null byte or (2) an MS-DOS deflatnuke · flatnuke | Средняя5,0 | — | 1,5 % | 10 авг. 2005 г. |
20Наблюдать | CVE-2005-2537Эксплойта нет | FlatNuke 2.5.5 and possibly earlier versions allows remote attackers to obtain sensitive information via a direct request to structure.php.flatnuke · flatnuke | Средняя5,0 | — | 1,5 % | 10 авг. 2005 г. |
19Наблюдать | CVE-2006-3608Proof of concept | The Gallery module in Simone Vellei Flatnuke 2.5.7 and earlier, when Gallery uploads are enabled, does not restrict the extensions of uploadflatnuke · flatnuke | Средняя4,6 | — | 2,3 % | 18 июл. 2006 г. |
18Наблюдать | CVE-2005-2539Proof of concept | Multiple cross-site scripting (XSS) vulnerabilities in FlatNuke 2.5.5 and possibly earlier versions allow remote attackers to inject arbitraflatnuke · flatnuke | Средняя4,3 | — | 2,5 % | 10 авг. 2005 г. |
18Наблюдать | CVE-2005-1895Proof of concept | Cross-site scripting (XSS) vulnerability in FlatNuke 2.5.3 allows remote attackers to inject arbitrary web script or HTML via the border or flatnuke · flatnuke | Средняя4,3 | — | 1,8 % | 9 июн. 2005 г. |
18Наблюдать | CVE-2005-2814Proof of concept | Cross-site scripting (XSS) vulnerability in FlatNuke 2.5.6 allows remote attackers to inject arbitrary web script or HTML via the usr parameflatnuke · flatnuke | Средняя4,3 | — | 1,7 % | 7 сент. 2005 г. |
17Наблюдать | CVE-2005-4449Proof of concept | verify.php in FlatNuke 2.5.6 allows remote authenticated administrators to modify arbitrary PHP files by setting the file parameter to an arflatnuke · flatnuke | Средняя4,0 | — | 4,6 % | 21 дек. 2005 г. |
17Наблюдать | CVE-2005-3306Эксплойта нет | Cross-site scripting (XSS) vulnerability in index.php for FlatNuke 2.5.6 allows remote attackers to inject arbitrary web script or HTML via flatnuke · flatnuke | Средняя4,3 | — | 1,2 % | 25 окт. 2005 г. |
17Наблюдать | CVE-2005-3361Эксплойта нет | Cross-site scripting (XSS) vulnerability in forum/index.php in FlatNuke 2.5.6 allows remote attackers to inject arbitrary web script or HTMLflatnuke · flatnuke | Средняя4,3 | — | 1,2 % | 27 окт. 2005 г. |
17Наблюдать | CVE-2007-5109Эксплойта нет | Cross-site request forgery (CSRF) vulnerability in index.php in FlatNuke 2.6, and possibly 3, allows remote attackers to change the passwordflatnuke · flatnuke · CWE-352 | Средняя4,3 | — | 0,6 % | 26 сент. 2007 г. |
- CVE-2005-444841В плане
FlatNuke 2.5.6 verifies authentication credentials based on an MD5 checksum of the admin name and the hashed password rather than the plaint
КритическаяCVSS 10,0Эксплойта нетEPSS 3 %flatnuke · flatnuke21 дек. 2005 г.
- CVE-2005-189431Наблюдать
Direct code injection vulnerability in FlatNuke 2.5.3 allows remote attackers to execute arbitrary PHP code by placing the code into the Ref
ВысокаяCVSS 7,5Proof of conceptEPSS 4 %flatnuke · flatnuke9 июн. 2005 г.
- CVE-2005-026731Наблюдать
index.php in FlatNuke 2.5.1 allows remote attackers to create an administrator account via carriage returns and #10 in the url_avatar field,
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %flatnuke · flatnuke2 мая 2005 г.
- CVE-2005-026830Наблюдать
Direct code injection vulnerability in FlatNuke 2.5.1 allows remote attackers to execute arbitrary PHP code by placing the code into the url
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %flatnuke · flatnuke3 янв. 2005 г.
- CVE-2005-189226Наблюдать
FlatNuke 2.5.3 allows remote attackers to cause a denial of service or obtain sensitive information via (1) a direct request to foot_news.ph
СредняяCVSS 6,4Эксплойта нетEPSS 2 %flatnuke · flatnuke9 июн. 2005 г.
- CVE-2005-281526Наблюдать
print.php in FlatNuke 2.5.6 allows remote attackers to obtain sensitive information (path disclosure on error) or cause a denial of service
СредняяCVSS 6,4Эксплойта нетEPSS 2 %flatnuke · flatnuke7 сент. 2005 г.
- CVE-2005-420822Наблюдать
Directory traversal vulnerability in Flatnuke 2.5.6 allows remote attackers to access arbitrary files via a ..
СредняяCVSS 5,0Proof of conceptEPSS 8 %flatnuke · flatnuke13 дек. 2005 г.
- CVE-2005-281322Наблюдать
Directory traversal vulnerability in FlatNuke 2.5.6 and possibly earlier allows remote attackers to read arbitrary files via ".." sequences
СредняяCVSS 5,0Proof of conceptEPSS 7 %flatnuke · flatnuke7 сент. 2005 г.
- CVE-2005-254022Наблюдать
CRLF injection vulnerability in FlatNuke 2.5.5 and possibly earlier versions allows remote attackers to execute arbitrary PHP commands via a
СредняяCVSS 5,0Proof of conceptEPSS 6 %flatnuke · flatnuke10 авг. 2005 г.
- CVE-2005-330721Наблюдать
Directory traversal vulnerability in index.php for FlatNuke 2.5.6 allows remote attackers to read arbitrary files via ".." sequences in the
СредняяCVSS 5,0Proof of conceptEPSS 3 %flatnuke · flatnuke25 окт. 2005 г.
- CVE-2005-189321Наблюдать
FlatNuke 2.5.3 allows remote attackers to obtain sensitive information via invalid parameters to certain scripts, which leaks the web docume
СредняяCVSS 5,0Proof of conceptEPSS 3 %flatnuke · flatnuke9 июн. 2005 г.
- CVE-2005-189621Наблюдать
Directory traversal vulnerability in thumb.php in FlatNuke 2.5.3 allows remote attackers to read arbitrary images or obtain the installation
СредняяCVSS 5,0Эксплойта нетEPSS 2 %flatnuke · flatnuke9 июн. 2005 г.
- CVE-2005-253820Наблюдать
FlatNuke 2.5.5 and possibly earlier versions allows remote attackers to obtain sensitive information via (1) a null byte or (2) an MS-DOS de
СредняяCVSS 5,0Эксплойта нетEPSS 2 %flatnuke · flatnuke10 авг. 2005 г.
- CVE-2005-253720Наблюдать
FlatNuke 2.5.5 and possibly earlier versions allows remote attackers to obtain sensitive information via a direct request to structure.php.
СредняяCVSS 5,0Эксплойта нетEPSS 2 %flatnuke · flatnuke10 авг. 2005 г.
- CVE-2006-360819Наблюдать
The Gallery module in Simone Vellei Flatnuke 2.5.7 and earlier, when Gallery uploads are enabled, does not restrict the extensions of upload
СредняяCVSS 4,6Proof of conceptEPSS 2 %flatnuke · flatnuke18 июл. 2006 г.
- CVE-2005-253918Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in FlatNuke 2.5.5 and possibly earlier versions allow remote attackers to inject arbitra
СредняяCVSS 4,3Proof of conceptEPSS 3 %flatnuke · flatnuke10 авг. 2005 г.
- CVE-2005-189518Наблюдать
Cross-site scripting (XSS) vulnerability in FlatNuke 2.5.3 allows remote attackers to inject arbitrary web script or HTML via the border or
СредняяCVSS 4,3Proof of conceptEPSS 2 %flatnuke · flatnuke9 июн. 2005 г.
- CVE-2005-281418Наблюдать
Cross-site scripting (XSS) vulnerability in FlatNuke 2.5.6 allows remote attackers to inject arbitrary web script or HTML via the usr parame
СредняяCVSS 4,3Proof of conceptEPSS 2 %flatnuke · flatnuke7 сент. 2005 г.
- CVE-2005-444917Наблюдать
verify.php in FlatNuke 2.5.6 allows remote authenticated administrators to modify arbitrary PHP files by setting the file parameter to an ar
СредняяCVSS 4,0Proof of conceptEPSS 5 %flatnuke · flatnuke21 дек. 2005 г.
- CVE-2005-330617Наблюдать
Cross-site scripting (XSS) vulnerability in index.php for FlatNuke 2.5.6 allows remote attackers to inject arbitrary web script or HTML via
СредняяCVSS 4,3Эксплойта нетEPSS 1 %flatnuke · flatnuke25 окт. 2005 г.
- CVE-2005-336117Наблюдать
Cross-site scripting (XSS) vulnerability in forum/index.php in FlatNuke 2.5.6 allows remote attackers to inject arbitrary web script or HTML
СредняяCVSS 4,3Эксплойта нетEPSS 1 %flatnuke · flatnuke27 окт. 2005 г.
- CVE-2007-510917Наблюдать
Cross-site request forgery (CSRF) vulnerability in index.php in FlatNuke 2.6, and possibly 3, allows remote attackers to change the password
СредняяCVSS 4,3Эксплойта нетEPSS 1 %flatnuke · flatnuke26 сент. 2007 г.