First published: Thu Feb 10 2005(Updated: )
index.php in FlatNuke 2.5.1 allows remote attackers to create an administrator account via carriage returns and #10 in the url_avatar field, which is interpreted as a sensitive directive.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Postnuke Software Foundation Pnphpbb | =2.5.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-0267 has a high severity rating due to its potential to allow remote attackers to gain administrative access.
To fix CVE-2005-0267, you should upgrade FlatNuke to the latest version that has addressed this vulnerability.
The impact of CVE-2005-0267 includes unauthorized administrative access, which can compromise the entire FlatNuke application.
CVE-2005-0267 specifically affects FlatNuke version 2.5.1.
Attackers can exploit CVE-2005-0267 by manipulating the url_avatar field with carriage returns to create unauthorized administrator accounts.