First published: Thu Nov 01 2007(Updated: )
Cross-site request forgery (CSRF) vulnerability in index.php in the File Manager module in Flatnuke 3 allows remote attackers to perform certain actions as administrators via requests containing the pathname in the dir parameter and the filename in the ffile parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Postnuke Software Foundation Pnphpbb |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-5773 is considered a medium severity vulnerability due to its ability to allow unauthorized actions as administrators.
To fix CVE-2007-5773, update the Flatnuke software to the latest version that addresses this CSRF vulnerability.
CVE-2007-5773 allows attackers to execute unauthorized actions within the File Manager module, potentially manipulating files as an administrator.
CVE-2007-5773 affects the File Manager module in Flatnuke 3.
In the context of CVE-2007-5773, cross-site request forgery allows attackers to perform actions on behalf of an authenticated user without their consent.