CVE-2005-3307
FlatNuke 2.5.6 - Directory Traversal via User or Quale Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2005-3307. PoCs published by [email protected].
AI-analyzed exploit summary The provided text describes multiple remote file include vulnerabilities in FlatNuke due to improper input sanitization. It includes example URLs demonstrating the vulnerabilities but lacks executable exploit code.
Description
Directory traversal vulnerability in index.php for FlatNuke 2.5.6 allows remote attackers to read arbitrary files via ".." sequences in the (1) user parameter in a profile operation or (2) quale parameter in a newtopic operation.
Exploits (1)
The provided text describes multiple remote file include vulnerabilities in FlatNuke due to improper input sanitization. It includes example URLs demonstrating the vulnerabilities but lacks executable exploit code.