FlatNuke 2.5.5

CPE Details

FlatNuke 2.5.5
2.5.5
2023-12-28
12h54 +00:00
2023-12-28
12h54 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:flatnuke:flatnuke:2.5.5:*:*:*:*:*:*:*

Informations

Vendor

flatnuke

Product

flatnuke

Version

2.5.5

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2006-3608 2006-07-14 19h00 +00:00 The Gallery module in Simone Vellei Flatnuke 2.5.7 and earlier, when Gallery uploads are enabled, does not restrict the extensions of uploaded files that begin with a GIF header, which allows remote authenticated users to execute arbitrary PHP code via an uploaded .php file.
4.6
CVE-2005-2537 2005-08-10 02h00 +00:00 FlatNuke 2.5.5 and possibly earlier versions allows remote attackers to obtain sensitive information via a direct request to structure.php.
5
CVE-2005-2538 2005-08-10 02h00 +00:00 FlatNuke 2.5.5 and possibly earlier versions allows remote attackers to obtain sensitive information via (1) a null byte or (2) an MS-DOS device name such as AUX, CON, PRN, COM1, or LPT1 in the mod parameter.
5
CVE-2005-2539 2005-08-10 02h00 +00:00 Multiple cross-site scripting (XSS) vulnerabilities in FlatNuke 2.5.5 and possibly earlier versions allow remote attackers to inject arbitrary web script or HTML via the (1) bodycolor, (2) backimage, (3) theme, or (4) logo parameter to structure.php, (5) admin, (6) admin_mail, or (7) back parameter to footer.php, or (8) the message body in a news post.
4.3
CVE-2005-2540 2005-08-10 02h00 +00:00 CRLF injection vulnerability in FlatNuke 2.5.5 and possibly earlier versions allows remote attackers to execute arbitrary PHP commands via an ASCII char 13 (carriage return) in the signature field, which is injected into a PHP script without a preceding comment character, which can then be executed by a direct request.
5