CVE-2005-2540
Estado: ModificadaMedia (5)—💥 Exploit
CRLF injection vulnerability in FlatNuke 2.5.5 and possibly earlier versions allows remote attackers to execute arbitrary PHP commands via an ASCII char 13 (carriage return) in the signature field, which is injected into a PHP script without a preceding comment character, which can then be executed by a direct request.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N
- Puntuación base: 5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 6.10%
- Percentil entre todas las CVEs puntuadas: 93
- Fecha de la puntuación: 7/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
💥 Exploits públicos
Hay código de explotación o plantillas de detección públicos. No es lo mismo que explotación activa confirmada (KEV), pero aumenta el riesgo: parchee con prioridad.
- Publicado en Exploit-DB · Flatnuke 2.5.5 - Remote Code Execution (8/8/2005)
Tecnologías afectadas (1)
CWE
- NVD-CWE-Other
Referencias
- http://marc.info/?l=bugtraq&m=112327238030127&w=2
- http://secunia.com/advisories/16330
- http://www.osvdb.org/18554
- http://www.rgod.altervista.org/flatnuke.html
- http://www.securityfocus.com/bid/14485
- https://exchange.xforce.ibmcloud.com/vulnerabilities/21709
- http://marc.info/?l=bugtraq&m=112327238030127&w=2
- http://secunia.com/advisories/16330
- http://www.osvdb.org/18554
- http://www.rgod.altervista.org/flatnuke.html
- http://www.securityfocus.com/bid/14485
- https://exchange.xforce.ibmcloud.com/vulnerabilities/21709
JSON original (NVD)
Mostrar
{
"id": "CVE-2005-2540",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:N/I:P/A:N",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2005-08-10T04:00:00.000",
"references": [
{
"url": "http://marc.info/?l=bugtraq&m=112327238030127&w=2",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/16330",
"source": "cve@mitre.org"
},
{
"url": "http://www.osvdb.org/18554",
"source": "cve@mitre.org"
},
{
"url": "http://www.rgod.altervista.org/flatnuke.html",
"tags": [
"Exploit"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/14485",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/21709",
"source": "cve@mitre.org"
},
{
"url": "http://marc.info/?l=bugtraq&m=112327238030127&w=2",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/16330",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.osvdb.org/18554",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.rgod.altervista.org/flatnuke.html",
"tags": [
"Exploit"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/14485",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/21709",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "CRLF injection vulnerability in FlatNuke 2.5.5 and possibly earlier versions allows remote attackers to execute arbitrary PHP commands via an ASCII char 13 (carriage return) in the signature field, which is injected into a PHP script without a preceding comment character, which can then be executed by a direct request."
}
],
"lastModified": "2026-06-16T22:15:10.037",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:flatnuke:flatnuke:2.5.5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "80720E0A-2E73-47B2-BA0E-4CFA177F5BFA"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}