CVE-2005-1894 Information

Description

Direct code injection vulnerability in FlatNuke 2.5.3 allows remote attackers to execute arbitrary PHP code by placing the code into the Referer header of an HTTP request which causes the code to be injected into referer.php which can then be accessed by the attacker.

Reference

http://flatnuke.sourceforge.net/index.php?mod=read&id=1117979256 http://secunia.com/advisories/15603 http://securitytracker.com/id?1014114 http://secwatch.org/advisories/secwatch/20050604_flatnuke.txt http://www.vupen.com/english/advisories/2005/0697

Share on: