flatnuke.sourceforge.netConfirmation
http://flatnuke.sourceforge.net/index.php?mod=read&id=1117979256 CVE-2005-1894
FlatNuke 2.5.x - 'referer.php' Crafted Referer Arbitrary PHP Code Execution
Record summary
CVE-2005-1894 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.
Description
Direct code injection vulnerability in FlatNuke 2.5.3 allows remote attackers to execute arbitrary PHP code by placing the code into the Referer header of an HTTP request, which causes the code to be injected into referer.php, which can then be accessed by the attacker.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBFlatNuke 2.5.x - 'referer.php' Crafted Referer Arbitrary PHP Code ExecutionExploitDB exploitby SecWatchNot analyzed1 file
References
615603Third-party advisory
http://secunia.com/advisories/15603 1014114vdb entry
http://securitytracker.com/id?1014114 secwatch.org
http://secwatch.org/advisories/secwatch/20050604_flatnuke.txt ADV-2005-0697vdb entry
http://www.vupen.com/english/advisories/2005/0697 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2005-1894