First published: Wed Sep 07 2005(Updated: )
Directory traversal vulnerability in FlatNuke 2.5.6 and possibly earlier allows remote attackers to read arbitrary files via ".." sequences and "%00" (trailing null byte) characters in the id parameter to the read mod in index.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Postnuke Software Foundation Pnphpbb | =2.5.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-2813 is considered a medium severity vulnerability due to its potential to allow remote file access.
To fix CVE-2005-2813, upgrade to the latest version of FlatNuke that addresses this vulnerability.
CVE-2005-2813 affects FlatNuke versions 2.5.6 and possibly earlier versions.
CVE-2005-2813 enables directory traversal attacks allowing unauthorized access to system files.
Yes, exploitation of CVE-2005-2813 can result in data breaches due to unauthorized file access.