{"api_version":"1","generated_at":"2026-07-23T10:45:46+00:00","cve":"CVE-2005-1894","urls":{"html":"https://cve.report/CVE-2005-1894","api":"https://cve.report/api/cve/CVE-2005-1894.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2005-1894","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2005-1894"},"summary":{"title":"CVE-2005-1894","description":"Direct code injection vulnerability in FlatNuke 2.5.3 allows remote attackers to execute arbitrary PHP code by placing the code into the Referer header of an HTTP request, which causes the code to be injected into referer.php, which can then be accessed by the attacker.","state":"PUBLISHED","assigner":"mitre","published_at":"2005-06-09 04:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["CWE-94","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://www.vupen.com/english/advisories/2005/0697","name":"http://www.vupen.com/english/advisories/2005/0697","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"Webmail - OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/15603","name":"http://secunia.com/advisories/15603","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Patch","Vendor Advisory"],"title":"Secunia - Advisories - FlatNuke Multiple Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securitytracker.com/id?1014114","name":"http://securitytracker.com/id?1014114","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Exploit","Patch","Third Party Advisory","VDB Entry"],"title":"SecurityTracker.com Archives - FlatNuke Referer Input Validation Hole Lets Remote Users Execute Arbitrary Commands","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secwatch.org/advisories/secwatch/20050604_flatnuke.txt","name":"http://secwatch.org/advisories/secwatch/20050604_flatnuke.txt","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Exploit","Patch","Vendor Advisory"],"title":"SEC Watch – Keeping an Eye on Out","mime":"text/plain","httpstatus":"200","archivestatus":"200"},{"url":"http://flatnuke.sourceforge.net/index.php?mod=read&id=1117979256","name":"http://flatnuke.sourceforge.net/index.php?mod=read&id=1117979256","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Product"],"title":"FlatNuke download | SourceForge.net","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2005-1894","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2005-1894","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2005","cve_id":"1894","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"flatnuke","cpe5":"flatnuke","cpe6":"2.5.3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T22:06:57.716Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"1014114","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1014114"},{"name":"15603","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/15603"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://secwatch.org/advisories/secwatch/20050604_flatnuke.txt"},{"name":"ADV-2005-0697","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2005/0697"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://flatnuke.sourceforge.net/index.php?mod=read&id=1117979256"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2005-06-06T00:00:00.000Z","descriptions":[{"lang":"en","value":"Direct code injection vulnerability in FlatNuke 2.5.3 allows remote attackers to execute arbitrary PHP code by placing the code into the Referer header of an HTTP request, which causes the code to be injected into referer.php, which can then be accessed by the attacker."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2009-02-26T10:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"1014114","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1014114"},{"name":"15603","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/15603"},{"tags":["x_refsource_MISC"],"url":"http://secwatch.org/advisories/secwatch/20050604_flatnuke.txt"},{"name":"ADV-2005-0697","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2005/0697"},{"tags":["x_refsource_CONFIRM"],"url":"http://flatnuke.sourceforge.net/index.php?mod=read&id=1117979256"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2005-1894","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Direct code injection vulnerability in FlatNuke 2.5.3 allows remote attackers to execute arbitrary PHP code by placing the code into the Referer header of an HTTP request, which causes the code to be injected into referer.php, which can then be accessed by the attacker."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"1014114","refsource":"SECTRACK","url":"http://securitytracker.com/id?1014114"},{"name":"15603","refsource":"SECUNIA","url":"http://secunia.com/advisories/15603"},{"name":"http://secwatch.org/advisories/secwatch/20050604_flatnuke.txt","refsource":"MISC","url":"http://secwatch.org/advisories/secwatch/20050604_flatnuke.txt"},{"name":"ADV-2005-0697","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2005/0697"},{"name":"http://flatnuke.sourceforge.net/index.php?mod=read&id=1117979256","refsource":"CONFIRM","url":"http://flatnuke.sourceforge.net/index.php?mod=read&id=1117979256"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2005-1894","datePublished":"2005-06-08T04:00:00.000Z","dateReserved":"2005-06-08T00:00:00.000Z","dateUpdated":"2024-08-07T22:06:57.716Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2005-06-09 04:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["CWE-94","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":true,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:flatnuke:flatnuke:2.5.3:*:*:*:*:*:*:*","matchCriteriaId":"E35353BC-BB2E-4702-BC8D-9809617199F9"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2005","CveId":"1894","Ordinal":"1","Title":"CVE-2005-1894","CVE":"CVE-2005-1894","Year":"2005"},"notes":[{"CveYear":"2005","CveId":"1894","Ordinal":"1","NoteData":"Direct code injection vulnerability in FlatNuke 2.5.3 allows remote attackers to execute arbitrary PHP code by placing the code into the Referer header of an HTTP request, which causes the code to be injected into referer.php, which can then be accessed by the attacker.","Type":"Description","Title":"CVE-2005-1894"},{"CveYear":"2005","CveId":"1894","Ordinal":"2","NoteData":"2005-06-08","Type":"Other","Title":"Published"},{"CveYear":"2005","CveId":"1894","Ordinal":"3","NoteData":"2009-02-26","Type":"Other","Title":"Modified"}]}}}