Record summary

CVE-2005-1894 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.

Description

Direct code injection vulnerability in FlatNuke 2.5.3 allows remote attackers to execute arbitrary PHP code by placing the code into the Referer header of an HTTP request, which causes the code to be injected into referer.php, which can then be accessed by the attacker.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBFlatNuke 2.5.x - 'referer.php' Crafted Referer Arbitrary PHP Code ExecutionExploitDB exploitby SecWatchNot analyzed1 file
ExploitDB

PoC details

References

6