FlatNuke 2.5.3 allows remote malicious users to cause a denial of service or obtain sensitive information via (1) a direct request to foot_news.php, which triggers an infinite loop, or (2) direct requests to unknown scripts, which reveals the web document root in an error message.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
flatnuke flatnuke |