CVE: CVE-2005-1894

Export to Word

Direct code injection vulnerability in FlatNuke 2.5.3 allows remote attackers to execute arbitrary PHP code by placing the code into the Referer header of an HTTP request, which causes the code to be injected into referer.php, which can then be accessed by the attacker.

Threat-Mapped Scoring

Score: 0.0

Priority: Unclassified

EPSS

Score: 0.07813
Percentile: 0.91547

CVSS Scoring

CVSS v2 Score: 7.5

Severity:

Mapped CWE(s)

All CAPEC(s)

CAPEC(s) with Mapped TTPs

Mapped ATT&CK TTPs

Malware

APTs Threat Group Associations

Campaigns

Affected Products

← Back to Home