MEDIUM
Direct static code injection vulnerability in the download module in Flatnuke 3 allows remote authenticated administrators to inject arbitrary PHP code into a description.it.php file in a subdirectory of Download/ by saving a description and setting fneditmode to 1
Published Nov 1, 2007
6.0
MEDIUMCVSS 2.0
EPSS 3.83%
Description
Affected products
Remediation
Metrics
References (3)
Change history (0)
No recorded changes yet.