peter bassill · operator
$ cve CVE-2005-2540 JSON

CVE-2005-2540 EXPLOIT

5.0
MEDIUM · CVSS 2.0 · EPSS 6.1% (pctl 93)

Patch early

A public exploit exists.

Description

CRLF injection vulnerability in FlatNuke 2.5.5 and possibly earlier versions allows remote attackers to execute arbitrary PHP commands via an ASCII char 13 (carriage return) in the signature field, which is injected into a PHP script without a preceding comment character, which can then be executed by a direct request.

Scoring

CVSS5.0 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
EPSS6.1% — more likely to be exploited than 93% of all CVEs
On CISA KEVno
Public exploityes
Published2005-08-10
Last modified2026-06-16

Affected (1)

VendorProduct
flatnukeflatnuke

Public exploits

SourceTitleDate
exploit-dbFlatnuke 2.5.5 - Remote Code Execution2005-08-08

References

→ the Explorer  ·  watch your stack  ·  NVD