CVE-2005-2540

FlatNuke 2.5.5 - Remote Code Execution via CRLF Injection in Signature Field

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2005-2540.

AI-analyzed exploit summary This PHP script exploits a remote code execution vulnerability in FlatNuke 2.5.5 by injecting malicious code into the user registration process, creating a backdoor file that executes arbitrary commands via HTTP GET requests.

Description

CRLF injection vulnerability in FlatNuke 2.5.5 and possibly earlier versions allows remote attackers to execute arbitrary PHP commands via an ASCII char 13 (carriage return) in the signature field, which is injected into a PHP script without a preceding comment character, which can then be executed by a direct request.

Exploits (1)

exploitdb WORKING POC
phpwebappsphp
https://www.exploit-db.com/exploits/1140

This PHP script exploits a remote code execution vulnerability in FlatNuke 2.5.5 by injecting malicious code into the user registration process, creating a backdoor file that executes arbitrary commands via HTTP GET requests.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: FlatNuke 2.5.5 (possibly prior versions)
No auth needed
Prerequisites: Target must have FlatNuke 2.5.5 or earlier installed · PHP must be configured with allow_call_time_pass_reference and register_globals enabled
devstral-2 · analyzed Feb 19, 2026 Full analysis →

References (6)

Core 6
Core References
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=112327238030127&w=2
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/16330
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/21709
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/18554
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/14485

Scores

EPSS 0.0632
EPSS Percentile 91.2%

Details

Status published
Products (1)
flatnuke/flatnuke 2.5.5
Published Aug 10, 2005
Tracked Since Feb 18, 2026