Back

CVE-2005-1894

Direct code injection vulnerability in FlatNuke 2.5.3 allows remote attackers to execute arbitrary PHP code by placing the code into the Referer header of an HTTP request, which causes the code to be injected into referer.php, which can then be accessed by the attacker.

Published: Jun 9, 2005 Modified: Jun 16, 2026
CWE-94

CVSS Metrics

Affected Products (1)

Vendor Product Version
flatnuke flatnuke 2.5.3

GitHub Security Advisory GHSA-mjp9-35c3-rjjh

Direct code injection vulnerability in FlatNuke 2.5.3 allows remote attackers to execute...

References (10)

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 3.72%

Top 11% most likely to be exploited

Threat Score 31.1 / 100

Data Sources

NVD EPSS GitHub