Back
CVE-2005-2540
CRLF injection vulnerability in FlatNuke 2.5.5 and possibly earlier versions allows remote attackers to execute arbitrary PHP commands via an ASCII char 13 (carriage return) in the signature field, which is injected into a PHP script without a preceding comment character, which can then be executed by a direct request.
Published: Aug 10, 2005
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (1)
| Vendor | Product | Version |
|---|---|---|
| flatnuke | flatnuke | 2.5.5 |
GitHub Security Advisory GHSA-x95g-j2cv-5p33
CRLF injection vulnerability in FlatNuke 2.5.5 and possibly earlier versions allows remote...
References (12)
- http://marc.info/?l=bugtraq&m=112327238030127&w=2
- http://secunia.com/advisories/16330
- http://www.osvdb.org/18554
- http://www.rgod.altervista.org/flatnuke.html Exploit
- http://www.securityfocus.com/bid/14485
- https://exchange.xforce.ibmcloud.com/vulnerabilities/21709
- http://marc.info/?l=bugtraq&m=112327238030127&w=2
- http://secunia.com/advisories/16330
- http://www.osvdb.org/18554
- http://www.rgod.altervista.org/flatnuke.html Exploit
- http://www.securityfocus.com/bid/14485
- https://exchange.xforce.ibmcloud.com/vulnerabilities/21709
Risk Scores
CVSS Score
5.0 / 10
EPSS Score
6.10%
Top 7% most likely to be exploited
Threat Score
21.8 / 100
Data Sources
NVD
EPSS
GitHub