Vulnerability CVE-2005-4448


Published: 2005-12-21   Modified: 2012-02-12

Description:
FlatNuke 2.5.6 verifies authentication credentials based on an MD5 checksum of the admin name and the hashed password rather than the plaintext password, which allows attackers to gain privileges by obtaining the password hash (possibly via CVE-2005-2813), then calculating the credentials and including them in the secid cookie.

CVSS2 => (AV:N/AC:L/Au:N/C:C/I:C/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
10/10
10/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Complete
Complete
Complete
Affected software
Flatnuke -> Flatnuke 

 References:
http://cvs.sourceforge.net/viewcvs.py/flatnuke/flatnuke/Changelog?rev=1.78&view=markup
http://securitytracker.com/id?1015339
http://www.securityfocus.com/archive/1/419107
http://www.securityfocus.com/bid/15796
https://exchange.xforce.ibmcloud.com/vulnerabilities/22159

Copyright 2024, cxsecurity.com

 

Back to Top