Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2007-5772

Опубликовано: 01 нояб. 2007
Источник: nvd
CVSS2: 6
EPSS Низкий

Описание

Direct static code injection vulnerability in the download module in Flatnuke 3 allows remote authenticated administrators to inject arbitrary PHP code into a description.it.php file in a subdirectory of Download/ by saving a description and setting fneditmode to 1. NOTE: unauthenticated remote attackers can exploit this by leveraging a cookie manipulation issue.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:flatnuke3:flatnuke3:*:*:*:*:*:*:*:*

EPSS

Процентиль: 87%
0.03277
Низкий

6 Medium

CVSS2

Дефекты

CWE-94

Связанные уязвимости

github
почти 4 года назад

Direct static code injection vulnerability in the download module in Flatnuke 3 allows remote authenticated administrators to inject arbitrary PHP code into a description.it.php file in a subdirectory of Download/ by saving a description and setting fneditmode to 1. NOTE: unauthenticated remote attackers can exploit this by leveraging a cookie manipulation issue.

EPSS

Процентиль: 87%
0.03277
Низкий

6 Medium

CVSS2

Дефекты

CWE-94