Vulnerability index

Browse CVEs

13 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Flatnuke HIGH 10.0
CVE-2005-4448

FlatNuke 2.5.6 verifies authentication credentials based on an MD5 checksum of the admin name and the hashed password rather than the plaintext passw…

No fix yet
Fix from $1,950 2005-12-21
Flatnuke MEDIUM 5.0
CVE-2005-4208EPSS 8%

Directory traversal vulnerability in Flatnuke 2.5.6 allows remote attackers to access arbitrary files via a .. (dot dot) and null byte (%00) in the i…

No fix yet
Fix from $1,600 2005-12-13
Flatnuke MEDIUM 6.4
CVE-2005-2815

print.php in FlatNuke 2.5.6 allows remote attackers to obtain sensitive information (path disclosure on error) or cause a denial of service (resource…

No fix yet
Fix from $1,600 2005-09-07
Flatnuke MEDIUM 5.0
CVE-2005-2813EPSS 7%

Directory traversal vulnerability in FlatNuke 2.5.6 and possibly earlier allows remote attackers to read arbitrary files via ".." sequences and "%00"…

No fix yet
Fix from $1,600 2005-09-07
Flatnuke MEDIUM 5.0
CVE-2005-2537

FlatNuke 2.5.5 and possibly earlier versions allows remote attackers to obtain sensitive information via a direct request to structure.php.

No fix yet
Fix from $1,600 2005-08-10
Flatnuke MEDIUM 5.0
CVE-2005-2538

FlatNuke 2.5.5 and possibly earlier versions allows remote attackers to obtain sensitive information via (1) a null byte or (2) an MS-DOS device name…

No fix yet
Fix from $1,600 2005-08-10
Flatnuke MEDIUM 5.0
CVE-2005-2540EPSS 6%

CRLF injection vulnerability in FlatNuke 2.5.5 and possibly earlier versions allows remote attackers to execute arbitrary PHP commands via an ASCII c…

No fix yet
Fix from $1,600 2005-08-10
Flatnuke HIGH 7.5
CVE-2005-1894

Direct code injection vulnerability in FlatNuke 2.5.3 allows remote attackers to execute arbitrary PHP code by placing the code into the Referer head…

Patch available
Fix from $1,950 2005-06-09
Flatnuke MEDIUM 6.4
CVE-2005-1892

FlatNuke 2.5.3 allows remote attackers to cause a denial of service or obtain sensitive information via (1) a direct request to foot_news.php, which …

Fix: after 2.5.3
Fix from $1,600 2005-06-09
Flatnuke MEDIUM 5.0
CVE-2005-1893

FlatNuke 2.5.3 allows remote attackers to obtain sensitive information via invalid parameters to certain scripts, which leaks the web document root i…

Patch available
Fix from $1,600 2005-06-09
Flatnuke MEDIUM 5.0
CVE-2005-1896

Directory traversal vulnerability in thumb.php in FlatNuke 2.5.3 allows remote attackers to read arbitrary images or obtain the installation path via…

Patch available
Fix from $1,600 2005-06-09
Flatnuke HIGH 7.5
CVE-2005-0267

index.php in FlatNuke 2.5.1 allows remote attackers to create an administrator account via carriage returns and #10 in the url_avatar field, which is…

Patch available
Fix from $1,950 2005-05-02
Flatnuke HIGH 7.5
CVE-2005-0268

Direct code injection vulnerability in FlatNuke 2.5.1 allows remote attackers to execute arbitrary PHP code by placing the code into the url_avatar f…

Patch available
Fix from $1,950 2005-01-03