CVE-2005-1892

FlatNuke 2.5.3 allows remote attackers to cause a denial of service or obtain sensitive information via (1) a direct request to foot_news.php, which triggers an infinite loop, or (2) direct requests to unknown scripts, which reveals the web document root in an error message.
Configurations

Configuration 1 (hide)

cpe:2.3:a:flatnuke:flatnuke:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2005-06-09 04:00

Updated : 2024-01-25 21:10


NVD link : CVE-2005-1892

Mitre link : CVE-2005-1892

CVE.ORG link : CVE-2005-1892


JSON object : View

Products Affected

flatnuke

  • flatnuke
CWE
CWE-425

Direct Request ('Forced Browsing')