Flatnuke

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 22
    Known Exploited: 0
    1
    Critical Level Threats
    3
    High Level Threats
    18
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2007-5109

    Cross-site request forgery (CSRF) vulnerability in index.php in FlatNuke 2.6, and possibly 3, allows remote attackers to change the password and privilege level of arbitrary accounts via the user parameter and modified (1) regpass and (2) level parameters in a none_Login action, as demonstrated by using a Flash object to automatically make the request.

    Last Modified: Apr 23, 2026
    Published: Sep 26, 2007

    CVE-2006-3608

    The Gallery module in Simone Vellei Flatnuke 2.5.7 and earlier, when Gallery uploads are enabled, does not restrict the extensions of uploaded files that begin with a GIF header, which allows remote authenticated users to execute arbitrary PHP code via an uploaded .php file.

    Last Modified: Apr 16, 2026
    Published: Jul 14, 2006

    CVE-2005-4449

    verify.php in FlatNuke 2.5.6 allows remote authenticated administrators to modify arbitrary PHP files by setting the file parameter to an arbitrary file and injecting the code into the body parameter. NOTE: if a FlatNuke administrator is normally assumed to be able to modify arbitrary content, then this issue does not cross privilege boundaries and would not be a vulnerability.

    Last Modified: Apr 16, 2026
    Published: Dec 21, 2005

    CVE-2005-4448

    FlatNuke 2.5.6 verifies authentication credentials based on an MD5 checksum of the admin name and the hashed password rather than the plaintext password, which allows attackers to gain privileges by obtaining the password hash (possibly via CVE-2005-2813), then calculating the credentials and including them in the secid cookie.

    Last Modified: Apr 16, 2026
    Published: Dec 21, 2005

    CVE-2005-4208

    Directory traversal vulnerability in Flatnuke 2.5.6 allows remote attackers to access arbitrary files via a .. (dot dot) and null byte (%00) in the id parameter of the read module.

    Last Modified: Apr 16, 2026
    Published: Dec 13, 2005
    Items Per Page
    Flatnuke Vulnerabilities & Security CVEs | CVE-DB