First published: Wed Aug 10 2005(Updated: )
CRLF injection vulnerability in FlatNuke 2.5.5 and possibly earlier versions allows remote attackers to execute arbitrary PHP commands via an ASCII char 13 (carriage return) in the signature field, which is injected into a PHP script without a preceding comment character, which can then be executed by a direct request.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Postnuke Software Foundation Pnphpbb | =2.5.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-2540 has a medium severity as it allows remote execution of arbitrary PHP commands.
To fix CVE-2005-2540, upgrade to a newer version of FlatNuke that addresses this vulnerability.
CVE-2005-2540 affects FlatNuke version 2.5.5 and possibly earlier versions.
Yes, CVE-2005-2540 can be exploited remotely through crafted inputs in the signature field.
CVE-2005-2540 is associated with CRLF injection attacks that execute arbitrary PHP commands.