← Back

Flatnuke3

flatnuke3

Vendor: Flatnuke3 • 4 CVEs

CVEs (4)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Flatnuke3
1Flatnuke3
Apr 23, 2026
Nov 1, 2007
N/A· v4
N/A· v3
5.0 MEDIUM· v2
index.php in the File Manager module in Flatnuke 3 allows remote attackers to obtain sensitive information via an invalid argumentname parameter in a disc op action, which reveals the path in an error message.
1Flatnuke3
1Flatnuke3
Apr 23, 2026
Nov 1, 2007
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site request forgery (CSRF) vulnerability in index.php in the File Manager module in Flatnuke 3 allows remote attackers to perform certain actions as administrators via requests containing the pathname in the dir p...Show more
Cross-site request forgery (CSRF) vulnerability in index.php in the File Manager module in Flatnuke 3 allows remote attackers to perform certain actions as administrators via requests containing the pathname in the dir parameter and the filename in the ffile parameter.Show less
1Flatnuke3
1Flatnuke3
Apr 23, 2026
Nov 1, 2007
N/A· v4
N/A· v3
6.0 MEDIUM· v2
Direct static code injection vulnerability in the download module in Flatnuke 3 allows remote authenticated administrators to inject arbitrary PHP code into a description.it.php file in a subdirectory of Download/ by sav...Show more
Direct static code injection vulnerability in the download module in Flatnuke 3 allows remote authenticated administrators to inject arbitrary PHP code into a description.it.php file in a subdirectory of Download/ by saving a description and setting fneditmode to 1. NOTE: unauthenticated remote attackers can exploit this by leveraging a cookie manipulation issue.Show less
1Flatnuke3
1Flatnuke3
Apr 23, 2026
Nov 1, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
Flatnuke 3 (aka FlatnuX) allows remote attackers to obtain administrative access via a myforum%00 cookie.