CVE-2005-1894
Summary
| CVE | CVE-2005-1894 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2005-06-09 04:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | Direct code injection vulnerability in FlatNuke 2.5.3 allows remote attackers to execute arbitrary PHP code by placing the code into the Referer header of an HTTP request, which causes the code to be injected into referer.php, which can then be accessed by the attacker. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Webmail - OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Broken Link |
| Secunia - Advisories - FlatNuke Multiple Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Broken Link, Patch, Vendor Advisory |
| SecurityTracker.com Archives - FlatNuke Referer Input Validation Hole Lets Remote Users Execute Arbitrary Commands | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | Broken Link, Exploit, Patch, Third Party Advisory, VDB Entry |
| SEC Watch – Keeping an Eye on Out | af854a3a-2127-422b-91ae-364da2661108 | secwatch.org | Broken Link, Exploit, Patch, Vendor Advisory |
| FlatNuke download | SourceForge.net | af854a3a-2127-422b-91ae-364da2661108 | flatnuke.sourceforge.net | Patch, Product |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.