PT-2007-6740 · Flatnuke · Flatnuke

Kingoftheworld

·

Published

2007-11-01

·

Updated

2017-09-29

·

CVE-2007-5773

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Flatnuke version 3
Description A cross-site request forgery (CSRF) issue exists, allowing remote attackers to perform actions as administrators. This is achieved through requests that contain the pathname in the dir parameter and the filename in the ffile parameter.
Recommendations For Flatnuke version 3, consider restricting access to the File Manager module until a fix is available. As a temporary workaround, avoid using the dir and ffile parameters in requests to the index.php file.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2007-5773

Affected Products

Flatnuke