Vulnerability Assessment & Network Security Forums



If through a vulnerability assessment, a network security issue is detected for the vulnerability below, applying the appropriate security patches in a timely matter is very important.  If you have detected that your system has already been compromised, following CERT's Network Security recovery document will assist with recommended steps for system recovery.


Home >> Browse Vulnerability Assessment Database >> CGI abuses >> FlatNuke id Parameter Directory Traversal Vulnerability


Vulnerability Assessment Details

FlatNuke id Parameter Directory Traversal Vulnerability

Vulnerability Assessment Summary
Checks for id parameter directory traversal vulnerability in FlatNuke

Detailed Explanation for this Vulnerability Assessment

Summary :

The remote web server contains a PHP application that is affected by a
directory traversal vulnerability.

Description :

The remote host is running FlatNuke, a content management system
written in PHP and using flat files rather than a database for its
storage.

The version of FlatNuke installed on the remote host suffers fails to
remove directory traversal sequences user input to the 'id' parameter
of the 'index.php' script. Provided PHP's 'magic_quotes_gpc' setting
is enabled, a possible hacker can leverage this flaw to read arbitrary files
on the remote host subject to the rights of the web server user
id.

See also :

http://retrogod.altervista.org/flatnuke256_xpl.html

Solution :

Enable PHP's 'magic_quotes_gpc' setting.

Network Security Threat Level:

Critical / CVSS Base Score : 10.0
(AV:R/AC:L/Au:NR/C:C/I:C/A:C/B:N)

Networks Security ID: 14702, 15796

Vulnerability Assessment Copyright: This script is Copyright (C) 2005-2006 Tenable Network Security

Cables, Connectors


NEW Original OEM 60W Power Adapter Charger A1344 for APPLE 13

NEW Original OEM 60W Power Adapter Charger A1344 for APPLE 13" MacBook Pro A1278

$22.24



85W OEM NEW Power Adapter Charger For Apple Macbook Pro 13 15

85W OEM NEW Power Adapter Charger For Apple Macbook Pro 13 15" A1424 A1502 A1398

$24.24



Original OEM 87W USB-C Power Adapter Charger for Apple MacBook Pro 15

Original OEM 87W USB-C Power Adapter Charger for Apple MacBook Pro 15" 13" A1719

$28.44



OEM Apple MacBook Pro 13 A1706 A1708 2017 LCD Screen Display Assembly Silver picture

OEM Apple MacBook Pro 13 A1706 A1708 2017 LCD Screen Display Assembly Silver

$131.12



Genuine Apple A1718 61W USB-C Power Adapter Apple OEM CHARGER picture

Genuine Apple A1718 61W USB-C Power Adapter Apple OEM CHARGER

$24.99



Apple OEM Original (A1374) 45W MagSafe Power Adapter with Fold Plug Only - White picture

Apple OEM Original (A1374) 45W MagSafe Power Adapter with Fold Plug Only - White

$10.95



OEM 61W USB C Type C Adapter Charger for Apple MacBook PRO 13

OEM 61W USB C Type C Adapter Charger for Apple MacBook PRO 13" A1718 + Cable NEW

$23.00



APPLE OEM Original Cinema Display (Aluminum) Power Supply AC Adapter 65w or 90w picture

APPLE OEM Original Cinema Display (Aluminum) Power Supply AC Adapter 65w or 90w

$13.99



OEM Apple 10W GENUINE USB Wall Plug Charger Adapter iPhone iPad Lightning cable picture

OEM Apple 10W GENUINE USB Wall Plug Charger Adapter iPhone iPad Lightning cable

$6.99



OEM 30W USB-C Power Adapter Charger for apple MacBook Air iPhone 11 12 Pro +Cord picture

OEM 30W USB-C Power Adapter Charger for apple MacBook Air iPhone 11 12 Pro +Cord

$22.89



Discussions

No Discussions have been posted on this vulnerability.