Back

CVE-2005-2540

CRLF injection vulnerability in FlatNuke 2.5.5 and possibly earlier versions allows remote attackers to execute arbitrary PHP commands via an ASCII char 13 (carriage return) in the signature field, which is injected into a PHP script without a preceding comment character, which can then be executed by a direct request.

Published: Aug 10, 2005 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (1)

Vendor Product Version
flatnuke flatnuke 2.5.5

GitHub Security Advisory GHSA-x95g-j2cv-5p33

CRLF injection vulnerability in FlatNuke 2.5.5 and possibly earlier versions allows remote...

Risk Scores

CVSS Score 5.0 / 10
EPSS Score 6.10%

Top 7% most likely to be exploited

Threat Score 21.8 / 100

Data Sources

NVD EPSS GitHub