Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2005-2540

Опубликовано: 10 авг. 2005
Источник: nvd
CVSS2: 5
EPSS Низкий

Описание

CRLF injection vulnerability in FlatNuke 2.5.5 and possibly earlier versions allows remote attackers to execute arbitrary PHP commands via an ASCII char 13 (carriage return) in the signature field, which is injected into a PHP script without a preceding comment character, which can then be executed by a direct request.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:flatnuke:flatnuke:2.5.5:*:*:*:*:*:*:*

EPSS

Процентиль: 91%
0.0632
Низкий

5 Medium

CVSS2

Дефекты

NVD-CWE-Other

Связанные уязвимости

github
почти 4 года назад

CRLF injection vulnerability in FlatNuke 2.5.5 and possibly earlier versions allows remote attackers to execute arbitrary PHP commands via an ASCII char 13 (carriage return) in the signature field, which is injected into a PHP script without a preceding comment character, which can then be executed by a direct request.

EPSS

Процентиль: 91%
0.0632
Низкий

5 Medium

CVSS2

Дефекты

NVD-CWE-Other