Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x95g-j2cv-5p33

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

CRLF injection vulnerability in FlatNuke 2.5.5 and possibly earlier versions allows remote attackers to execute arbitrary PHP commands via an ASCII char 13 (carriage return) in the signature field, which is injected into a PHP script without a preceding comment character, which can then be executed by a direct request.

CRLF injection vulnerability in FlatNuke 2.5.5 and possibly earlier versions allows remote attackers to execute arbitrary PHP commands via an ASCII char 13 (carriage return) in the signature field, which is injected into a PHP script without a preceding comment character, which can then be executed by a direct request.

EPSS

Процентиль: 91%
0.0632
Низкий

Связанные уязвимости

nvd
больше 20 лет назад

CRLF injection vulnerability in FlatNuke 2.5.5 and possibly earlier versions allows remote attackers to execute arbitrary PHP commands via an ASCII char 13 (carriage return) in the signature field, which is injected into a PHP script without a preceding comment character, which can then be executed by a direct request.

EPSS

Процентиль: 91%
0.0632
Низкий