First published: Wed Jun 08 2005(Updated: )
Direct code injection vulnerability in FlatNuke 2.5.3 allows remote attackers to execute arbitrary PHP code by placing the code into the Referer header of an HTTP request, which causes the code to be injected into referer.php, which can then be accessed by the attacker.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Postnuke Software Foundation Pnphpbb | =2.5.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-1894 is rated as critical due to its ability to allow remote code execution.
To fix CVE-2005-1894, you should upgrade FlatNuke to a version later than 2.5.3 that addresses this vulnerability.
CVE-2005-1894 could allow attackers to execute arbitrary PHP code on your server, potentially compromising data integrity and confidentiality.
Any installation of FlatNuke version 2.5.3 is affected by CVE-2005-1894.
CVE-2005-1894 is classified as a direct code injection vulnerability.