CVE-2005-1892 Information

Description

FlatNuke 2.5.3 allows remote attackers to cause a denial of service or obtain sensitive information via (1) a direct request to foot_news.php which triggers an infinite loop or (2) direct requests to unknown scripts which reveals the web document root in an error message.

Reference

http://flatnuke.sourceforge.net/index.php?mod=read&id=1117979256 http://secunia.com/advisories/15603 http://securitytracker.com/id?1014114 http://secwatch.org/advisories/secwatch/20050604_flatnuke.txt http://www.vupen.com/english/advisories/2005/0697

Share on: