CVE-2005-4448
FlatNuke 2.5.6 verifies authentication credentials based on an MD5 checksum of the admin name and the hashed password rather than the plaintext password, which allows attackers to gain privileges by obtaining the password hash (possibly via CVE-2005-2813), then calculating the credentials and including them in the secid cookie.
- Affected products
- Flatnuke
- Flatnuke
- = 2.5.6
- Fix
- Available
- CVSS 2.0
- 10.0 HIGH
- EPSS
- 2.8% (85th percentile)
- NVD status
- Modified
- Published
- 2005-12-21
CVE-2005-4448 at NVD
No indexed exploits for CVE-2005-4448 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2005-4448 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.