peter bassill · operator
$ cve CVE-2005-1893 JSON

CVE-2005-1893 EXPLOIT

5.0
MEDIUM · CVSS 2.0 · EPSS 2.9% (pctl 87)

Patch early

A public exploit exists.

Description

FlatNuke 2.5.3 allows remote attackers to obtain sensitive information via invalid parameters to certain scripts, which leaks the web document root in an error message.

Scoring

CVSS5.0 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS2.93% — more likely to be exploited than 87% of all CVEs
On CISA KEVno
Public exploityes
Published2005-06-09
Last modified2026-06-16

Affected (1)

VendorProduct
flatnukeflatnuke

Public exploits

SourceTitleDate
exploit-dbFlatNuke 2.5.x - 'index.php?where' Full Path Disclosure2005-06-07

References

→ the Explorer  ·  watch your stack  ·  NVD