HIGH
FlatNuke 2.5.6 verifies authentication credentials based on an MD5 checksum of the admin name and the hashed password rather than the plaintext password, which allows attackers to gain privileges by obtaining the password hash (possibly via CVE-2005-2813), then calculating the credentials and including them in the secid cookie
Published Dec 21, 2005
10.0
HIGHCVSS 2.0
EPSS 2.82%
Description
Affected products
Remediation
Metrics
References (5)
Change history (0)
No recorded changes yet.