Search Results (22 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2005-4208 1 Flatnuke 1 Flatnuke 2025-04-03 N/A
Directory traversal vulnerability in Flatnuke 2.5.6 allows remote attackers to access arbitrary files via a .. (dot dot) and null byte (%00) in the id parameter of the read module.
CVE-2005-3306 1 Flatnuke 1 Flatnuke 2025-04-03 N/A
Cross-site scripting (XSS) vulnerability in index.php for FlatNuke 2.5.6 allows remote attackers to inject arbitrary web script or HTML via the user parameter in a profile operation, a different vulnerability than CVE-2005-2814. NOTE: it is possible that this XSS is a resultant vulnerability of CVE-2005-3307.