CVE-2005-1895

Flatnuke - XSS

Title source: rule
STIX 2.1

Description

Cross-site scripting (XSS) vulnerability in FlatNuke 2.5.3 allows remote attackers to inject arbitrary web script or HTML via the border or back parameters to (1) help.php or (2) footer.php.

Exploits (1)

exploitdb WRITEUP VERIFIED
by SecWatch · textwebappsphp
https://www.exploit-db.com/exploits/25800

References (5)

Core 5
Core References
Patch vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1014114
Patch third-party-advisory x_refsource_secunia
http://secunia.com/advisories/15603
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2005/0697

Scores

EPSS 0.0444
EPSS Percentile 89.1%

Details

Status published
Products (1)
flatnuke/flatnuke 2.5.3
Published Jun 09, 2005
Tracked Since Feb 18, 2026