peter bassill · operator
$ cve CVE-2005-1894 JSON

CVE-2005-1894 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 3.7% (pctl 90)

Patch early

A public exploit exists.

Description

Direct code injection vulnerability in FlatNuke 2.5.3 allows remote attackers to execute arbitrary PHP code by placing the code into the Referer header of an HTTP request, which causes the code to be injected into referer.php, which can then be accessed by the attacker.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS3.72% — more likely to be exploited than 90% of all CVEs
WeaknessCWE-94
On CISA KEVno
Public exploityes
Published2005-06-09
Last modified2026-06-16

Affected (1)

VendorProduct
flatnukeflatnuke

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD