Flatnuke
21 CVEs tracked since 2005. Since Feb 2005, none of them reached CISA KEV.
Flatnuke CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2005-02 | 2 | 0 |
| 2005-03 | null or fewer | |
| 2005-04 | null or fewer | |
| 2005-05 | null or fewer | |
| 2005-06 | 5 | 0 |
| 2005-07 | null or fewer | |
| 2005-08 | 4 | 0 |
| 2005-09 | 3 | 0 |
| 2005-10 | 2 | 0 |
| 2005-11 | null or fewer | |
| 2005-12 | 3 | 0 |
| 2006-01 | null or fewer | |
| 2006-02 | null or fewer | |
| 2006-03 | null or fewer | |
| 2006-04 | null or fewer | |
| 2006-05 | null or fewer | |
| 2006-06 | null or fewer | |
| 2006-07 | 1 | 0 |
| 2006-08 | null or fewer | |
| 2006-09 | null or fewer | |
| 2006-10 | null or fewer | |
| 2006-11 | null or fewer | |
| 2006-12 | null or fewer | |
| 2007-01 | null or fewer | |
| 2007-02 | null or fewer | |
| 2007-03 | null or fewer | |
| 2007-04 | null or fewer | |
| 2007-05 | null or fewer | |
| 2007-06 | null or fewer | |
| 2007-07 | null or fewer | |
| 2007-08 | null or fewer | |
| 2007-09 | 1 | 0 |
Products
The products that kept showing up in Flatnuke's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Flatnuke.
- CVE-2007-5109Cross-site request forgery (CSRF) vulnerability in index.php in FlatNuke 2.6, and possibly 3, allows remote attackers to change the password and privilege level of arbitrary accounts via the user p...4.3
- CVE-2006-3608The Gallery module in Simone Vellei Flatnuke 2.5.7 and earlier, when Gallery uploads are enabled, does not restrict the extensions of uploaded files that begin with a GIF header, which allows remot...4.6
- CVE-2005-4449verify.php in FlatNuke 2.5.6 allows remote authenticated administrators to modify arbitrary PHP files by setting the file parameter to an arbitrary file and injecting the code into the body paramet...4.0
- CVE-2005-4448FlatNuke 2.5.6 verifies authentication credentials based on an MD5 checksum of the admin name and the hashed password rather than the plaintext password, which allows attackers to gain privileges b...10.0
- CVE-2005-4208Directory traversal vulnerability in Flatnuke 2.5.6 allows remote attackers to access arbitrary files via a .. (dot dot) and null byte (%00) in the id parameter of the read module.5.0
- CVE-2005-3361Cross-site scripting (XSS) vulnerability in forum/index.php in FlatNuke 2.5.6 allows remote attackers to inject arbitrary web script or HTML via the nome parameter in a login operation, a variant o...4.3
- CVE-2005-3306Cross-site scripting (XSS) vulnerability in index.php for FlatNuke 2.5.6 allows remote attackers to inject arbitrary web script or HTML via the user parameter in a profile operation, a different vu...4.3
- CVE-2005-2815print.php in FlatNuke 2.5.6 allows remote attackers to obtain sensitive information (path disclosure on error) or cause a denial of service (resource consumption) via an MS-DOS device name in the n...6.4
- CVE-2005-2814Cross-site scripting (XSS) vulnerability in FlatNuke 2.5.6 allows remote attackers to inject arbitrary web script or HTML via the usr parameter in a vis_reg operation to index.php.4.3
- CVE-2005-2813Directory traversal vulnerability in FlatNuke 2.5.6 and possibly earlier allows remote attackers to read arbitrary files via ".." sequences and "%00" (trailing null byte) characters in the id param...5.0
- CVE-2005-2538FlatNuke 2.5.5 and possibly earlier versions allows remote attackers to obtain sensitive information via (1) a null byte or (2) an MS-DOS device name such as AUX, CON, PRN, COM1, or LPT1 in the mod...5.0
- CVE-2005-2539Multiple cross-site scripting (XSS) vulnerabilities in FlatNuke 2.5.5 and possibly earlier versions allow remote attackers to inject arbitrary web script or HTML via the (1) bodycolor, (2) backimag...4.3
- CVE-2005-2540CRLF injection vulnerability in FlatNuke 2.5.5 and possibly earlier versions allows remote attackers to execute arbitrary PHP commands via an ASCII char 13 (carriage return) in the signature field,...5.0
- CVE-2005-2537FlatNuke 2.5.5 and possibly earlier versions allows remote attackers to obtain sensitive information via a direct request to structure.php.5.0
- CVE-2005-1893FlatNuke 2.5.3 allows remote attackers to obtain sensitive information via invalid parameters to certain scripts, which leaks the web document root in an error message.5.0
The record
- Peak rank
- #18 in Jun 2005
- Busiest month shown
- Jun 2005, 5 CVEs
- Months with a KEV entry
- 0 since Feb 2005
- Monthly snapshots
- 8 since 2005