CVE-2005-2813 Information

Description

Directory traversal vulnerability in FlatNuke 2.5.6 and possibly earlier allows remote attackers to read arbitrary files via ..\ sequences and \00\ (trailing null byte) characters in the id parameter to the read mod in index.php.

Reference

http://seclists.org/lists/bugtraq/2005/Aug/0440.html http://secunia.com/advisories/16650/ http://securitytracker.com/id?1014824 http://securitytracker.com/id?1015339 http://www.securityfocus.com/archive/1/419107/100/0/threaded http://www.securityfocus.com/bid/14702 http://www.securityfocus.com/bid/15796

Share on: