Back
CVE-2005-1894
Direct code injection vulnerability in FlatNuke 2.5.3 allows remote attackers to execute arbitrary PHP code by placing the code into the Referer header of an HTTP request, which causes the code to be injected into referer.php, which can then be accessed by the attacker.
Published: Jun 9, 2005
Modified: Jun 16, 2026
CWE-94
CVSS Metrics
Affected Products (1)
| Vendor | Product | Version |
|---|---|---|
| flatnuke | flatnuke | 2.5.3 |
GitHub Security Advisory GHSA-mjp9-35c3-rjjh
Direct code injection vulnerability in FlatNuke 2.5.3 allows remote attackers to execute...
References (10)
- http://flatnuke.sourceforge.net/index.php?mod=read&id=1117979256 Patch, Product
- http://secunia.com/advisories/15603 Broken Link, Patch, Vendor Advisory
- http://securitytracker.com/id?1014114 Broken Link, Exploit, Patch, Third Party Advisory, VDB Entry
- http://secwatch.org/advisories/secwatch/20050604_flatnuke.txt Broken Link, Exploit, Patch, Vendor Advisory
- http://www.vupen.com/english/advisories/2005/0697 Broken Link
- http://flatnuke.sourceforge.net/index.php?mod=read&id=1117979256 Patch, Product
- http://secunia.com/advisories/15603 Broken Link, Patch, Vendor Advisory
- http://securitytracker.com/id?1014114 Broken Link, Exploit, Patch, Third Party Advisory, VDB Entry
- http://secwatch.org/advisories/secwatch/20050604_flatnuke.txt Broken Link, Exploit, Patch, Vendor Advisory
- http://www.vupen.com/english/advisories/2005/0697 Broken Link
Risk Scores
CVSS Score
7.5 / 10
EPSS Score
3.72%
Top 11% most likely to be exploited
Threat Score
31.1 / 100
Data Sources
NVD
EPSS
GitHub