Filtered by vendor Flatnuke Subscriptions
Filtered by product Flatnuke Subscriptions
Total 22 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2005-0267 1 Flatnuke 1 Flatnuke 2025-04-03 N/A
index.php in FlatNuke 2.5.1 allows remote attackers to create an administrator account via carriage returns and #10 in the url_avatar field, which is interpreted as a sensitive directive.
CVE-2005-1894 1 Flatnuke 1 Flatnuke 2025-04-03 N/A
Direct code injection vulnerability in FlatNuke 2.5.3 allows remote attackers to execute arbitrary PHP code by placing the code into the Referer header of an HTTP request, which causes the code to be injected into referer.php, which can then be accessed by the attacker.