10
CVE-2005-4448
- EPSS 2.82%
- Veröffentlicht 21.12.2005 11:03:00
- Zuletzt bearbeitet 16.06.2026 22:18:48
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
FlatNuke 2.5.6 verifies authentication credentials based on an MD5 checksum of the admin name and the hashed password rather than the plaintext password, which allows attackers to gain privileges by obtaining the password hash (possibly via CVE-2005-2813), then calculating the credentials and including them in the secid cookie.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2.82% | 0.847 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 10 | 10 | 10 |
AV:N/AC:L/Au:N/C:C/I:C/A:C
|
http://securitytracker.com/id?1015339
http://www.securityfocus.com/bid/15796
http://cvs.sourceforge.net/viewcvs.py/flatnuke/flatnuke/Changelog?rev=1.78&view=markup
http://www.securityfocus.com/archive/1/419107
https://exchange.xforce.ibmcloud.com/vulnerabilities/22159