Vulnerabilities > CVE-2005-2539 - Unspecified vulnerability in Flatnuke 2.5.5
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Multiple cross-site scripting (XSS) vulnerabilities in FlatNuke 2.5.5 and possibly earlier versions allow remote attackers to inject arbitrary web script or HTML via the (1) bodycolor, (2) backimage, (3) theme, or (4) logo parameter to structure.php, (5) admin, (6) admin_mail, or (7) back parameter to footer.php, or (8) the message body in a news post.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description | FlatNuke 2.5.5 footer.php Multiple Parameter XSS. CVE-2005-2539. Webapps exploit for php platform |
id | EDB-ID:26099 |
last seen | 2016-02-03 |
modified | 2005-08-05 |
published | 2005-08-05 |
reporter | rgod |
source | https://www.exploit-db.com/download/26099/ |
title | FlatNuke 2.5.5 footer.php Multiple Parameter XSS |
Nessus
NASL family | CGI abuses |
NASL id | FLATNUKE_256.NASL |
description | The remote host is running FlatNuke, a content management system written in PHP that uses flat files rather than a database for its storage. The version of FlatNuke installed on the remote host suffers from several flaws: - Arbitrary PHP Code Execution Vulnerability The application fails to remove newlines from a user |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 19396 |
published | 2005-08-08 |
reporter | This script is Copyright (C) 2005-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/19396 |
title | FlatNuke < 2.5.6 Multiple Remote Vulnerabilities |
code |
|
References
- http://marc.info/?l=bugtraq&m=112327238030127&w=2
- http://marc.info/?l=bugtraq&m=112327238030127&w=2
- http://secunia.com/advisories/16330
- http://secunia.com/advisories/16330
- http://www.osvdb.org/18551
- http://www.osvdb.org/18551
- http://www.osvdb.org/18552
- http://www.osvdb.org/18552
- http://www.osvdb.org/18553
- http://www.osvdb.org/18553
- http://www.rgod.altervista.org/flatnuke.html
- http://www.rgod.altervista.org/flatnuke.html
- http://www.securityfocus.com/bid/14483
- http://www.securityfocus.com/bid/14483
- https://exchange.xforce.ibmcloud.com/vulnerabilities/21707
- https://exchange.xforce.ibmcloud.com/vulnerabilities/21707
- https://exchange.xforce.ibmcloud.com/vulnerabilities/21708
- https://exchange.xforce.ibmcloud.com/vulnerabilities/21708