6.4

CVE-2005-1892

Exploit
FlatNuke 2.5.3 allows remote attackers to cause a denial of service or obtain sensitive information via (1) a direct request to foot_news.php, which triggers an infinite loop, or (2) direct requests to unknown scripts, which reveals the web document root in an error message.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
FlatnukeFlatnuke Version <= 2.5.3
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.16% 0.798
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.4 10 4.9
AV:N/AC:L/Au:N/C:P/I:N/A:P
CWE-425 Direct Request ('Forced Browsing')

The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.

http://flatnuke.sourceforge.net/index.php?mod=read&id=1117979256
Product
http://secunia.com/advisories/15603
Broken Link
http://securitytracker.com/id?1014114
Third Party Advisory
Exploit
Broken Link
VDB Entry
http://secwatch.org/advisories/secwatch/20050604_flatnuke.txt
Patch
Vendor Advisory
Broken Link
http://www.vupen.com/english/advisories/2005/0697
Broken Link