CVE-2007-5109

Cross-site request forgery (CSRF) vulnerability in index.php in FlatNuke 2.6, and possibly 3, allows remote attackers to change the password and privilege level of arbitrary accounts via the user parameter and modified (1) regpass and (2) level parameters in a none_Login action, as demonstrated by using a Flash object to automatically make the request.

Score4.3
Access VectorNETWORK
Access ComplexityMEDIUM
AuthenticationNONE
Confidentiality ImpactNONE
Integrity ImpactPARTIAL
Availability ImpactNONE
Published2007-09-26 07:17:00.000-04
Last Modified2018-10-15 05:40:23.000-04

Vulnerable Software List

VendorProductVersions
Flatnuke Flatnuke 2.6

References

SourceLink
SREASON3176
BUGTRAQ20070924 Arbitrary Command Inclusion
BID25817
XFflatnuke-mod-security-bypass(36763)