First published: Wed Aug 10 2005(Updated: )
FlatNuke 2.5.5 and possibly earlier versions allows remote attackers to obtain sensitive information via (1) a null byte or (2) an MS-DOS device name such as AUX, CON, PRN, COM1, or LPT1 in the mod parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Postnuke Software Foundation Pnphpbb | =2.5.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2005-2538 is considered low, as it primarily exposes sensitive information rather than allowing for remote code execution.
To fix CVE-2005-2538, upgrade to FlatNuke version 2.5.6 or later, which addresses the vulnerability.
CVE-2005-2538 allows attackers to exploit input validation issues using null bytes or MS-DOS device names to uncover sensitive information.
CVE-2005-2538 affects FlatNuke versions 2.5.5 and possibly earlier versions.
By exploiting CVE-2005-2538, attackers can gain access to sensitive file paths or other confidential data on the server.