← Back

CVE-2005-1894

nvd nist
Published: Jun 9, 2005Modified: Apr 16, 2026

JSON object

Loading...
7.5
Vector
AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploitability: 10.0 / Impact: 6.4
Source: NVD

Description

Direct code injection vulnerability in FlatNuke 2.5.3 allows remote attackers to execute arbitrary PHP code by placing the code into the Referer header of an HTTP request, which causes the code to be injected into referer.php, which can then be accessed by the attacker.

Affected (1)

Products: Flatnuke: Flatnuke
1 product
Flatnuke
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 2.5.3

References (10)

Source: cve@mitre.org
Broken LinkPatchVendor Advisory
Source: cve@mitre.org
Broken LinkExploitPatchThird Party AdvisoryVDB Entry
Source: cve@mitre.org
Broken LinkExploitPatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchProduct
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkPatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkExploitPatchThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkExploitPatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link

Timeline

No history available yet.