PT-2005-3692 · Flatnuke · Flatnuke
Retrogod
·
Published
2005-09-07
·
Updated
2017-07-11
·
CVE-2005-2815
CVSS v2.0
6.4
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
FlatNuke version 2.5.6
Description
The issue allows remote attackers to obtain sensitive information, such as path disclosure on error, or cause a denial of service due to resource consumption. This can be achieved by providing an MS-DOS device name in the
news parameter to "print.php", including device names like AUX, CON, PRN, COM1, or LPT1.Recommendations
For FlatNuke version 2.5.6, consider restricting access to the "print.php" file or validating the
news parameter to prevent the use of MS-DOS device names as a temporary workaround until a patch is available.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Flatnuke