PT-2005-2853 · Flatnuke · Flatnuke

Published

2005-06-08

·

Updated

2011-03-08

·

CVE-2005-1896

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions FlatNuke version 2.5.3
Description The issue allows remote attackers to read arbitrary images or obtain the installation path. This is achieved through a directory traversal vulnerability in the thumb.php file, utilizing the image parameter.
Recommendations For FlatNuke version 2.5.3, consider restricting access to the thumb.php file until a patch is available, or avoid using the image parameter in the affected API endpoint to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-1896

Affected Products

Flatnuke