CVE-2005-4448
Published Dec 21, 2005
Last updated 7 years ago
Overview
- Description
- FlatNuke 2.5.6 verifies authentication credentials based on an MD5 checksum of the admin name and the hashed password rather than the plaintext password, which allows attackers to gain privileges by obtaining the password hash (possibly via CVE-2005-2813), then calculating the credentials and including them in the secid cookie.
- Source
- cve@mitre.org
- NVD status
- Modified
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 10
- Impact score
- 10
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:C/I:C/A:C
Weaknesses
- nvd@nist.gov
- NVD-CWE-Other
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:flatnuke:flatnuke:2.5.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F59B925E-748F-4BC8-AF15-997CDAC9F9EE" } ], "operator": "OR" } ] } ]