Back

CVE-2005-2813

Directory traversal vulnerability in FlatNuke 2.5.6 and possibly earlier allows remote attackers to read arbitrary files via ".." sequences and "%00" (trailing null byte) characters in the id parameter to the read mod in index.php.

Published: Sep 7, 2005 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (1)

Vendor Product Version
flatnuke flatnuke 2.5.6

GitHub Security Advisory GHSA-v9mf-xpqx-f95x

Directory traversal vulnerability in FlatNuke 2.5.6 and possibly earlier allows remote attackers...

Risk Scores

CVSS Score 5.0 / 10
EPSS Score 6.94%

Top 6% most likely to be exploited

Threat Score 22.1 / 100

Data Sources

NVD EPSS GitHub