First published: Wed Sep 07 2005(Updated: )
print.php in FlatNuke 2.5.6 allows remote attackers to obtain sensitive information (path disclosure on error) or cause a denial of service (resource consumption) via an MS-DOS device name in the news parameter to print.php, such as (1) AUX, (2) CON, (3) PRN, (4) COM1, or (5) LPT1.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Postnuke Software Foundation Pnphpbb | =2.5.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2005-2815 is classified as medium due to its potential for sensitive information disclosure and denial of service.
To fix CVE-2005-2815, update to a later version of FlatNuke that addresses this vulnerability.
CVE-2005-2815 can be exploited through path disclosure and denial of service attacks by using specific MS-DOS device names in the news parameter.
CVE-2005-2815 specifically affects FlatNuke version 2.5.6.
Yes, CVE-2005-2815 can lead to sensitive information exposure through path disclosure on error.