CVE-2005-1895

Cross-site scripting (XSS) vulnerability in FlatNuke 2.5.3 allows remote attackers to inject arbitrary web script or HTML via the border or back parameters to (1) help.php or (2) footer.php.

Score4.3
Access VectorNETWORK
Access ComplexityMEDIUM
AuthenticationNONE
Confidentiality ImpactNONE
Integrity ImpactPARTIAL
Availability ImpactNONE
Published2005-06-09 12:00:00.000-04
Last Modified2011-03-07 09:23:03.000-05

Vulnerable Software List

VendorProductVersions
Flatnuke Flatnuke 2.5.3

References

SourceLink
CONFIRMhttp://flatnuke.sourceforge.net/index.php?mod=read&id=1117979256
SECTRACK1014114
MISChttp://secwatch.org/advisories/secwatch/20050604_flatnuke.txt
VUPENADV-2005-0697