|
|
Info |
Last Modified |
| 5 months ago |
|
|
|
|
Description |
FlatNuke contains a flaw that may allow a remote attacker to upload and execute arbitrary code. An input validation error exists in the authentication process when checking the "myforum" cookie parameter, this can be exploited to execute arbitrary code on the web server.
|
|
Classification |
Location:
Remote/Network Access Required
Attack Type:
Authentication Management
Impact:
Loss of Confidentiality,
Loss of Integrity
Exploit:
Exploit Available
Disclosure:
OSVDB Verified
OSVDB:
Web Related
|
|
Solution |
Upgrade to version 2.5.8.1 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.
|
|
Products |
|
FlatNuke
 |
2.5.8 |
|
|
|
|
Credit |
- rgod - rgod
autistici.org - http://retrogod.altervista.org
|
|
BlogsProvided by Technorati
|
None found at this time
|
|
|