First published: Wed Dec 21 2005(Updated: )
verify.php in FlatNuke 2.5.6 allows remote authenticated administrators to modify arbitrary PHP files by setting the file parameter to an arbitrary file and injecting the code into the body parameter. NOTE: if a FlatNuke administrator is normally assumed to be able to modify arbitrary content, then this issue does not cross privilege boundaries and would not be a vulnerability.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Postnuke Software Foundation Pnphpbb | =2.5.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-4449 is considered a critical vulnerability due to its ability to allow authenticated administrators to inject arbitrary code into PHP files.
To fix CVE-2005-4449, upgrade to the latest version of FlatNuke that has patched this vulnerability.
CVE-2005-4449 affects FlatNuke version 2.5.6.
Yes, CVE-2005-4449 can be exploited remotely by authenticated administrators.
CVE-2005-4449 is a local file inclusion vulnerability that allows code injection.