vendor:
Flatnux CMS
by:
girex
8,8
CVSS
HIGH
Local File Inclusion
98
CWE
Product Name: Flatnux CMS
Affected Version From: 2009-03-27
Affected Version To: 2009-03-27
Patch Exists: YES
Related CWE: N/A
CPE: a:flatnux:flatnux:2009-03-27
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2009
Multiple Remote Vulnerabilities in Flatnux CMS
Flatnux suffers from multiple local file inclusions, which can be exploited by malicious people to include arbitrary files from local resources. Successful exploitation requires that 'register_globals' is set to 'on'. The vulnerabilities are located in multiple files, such as 'admin.php', 'search.php', 'section.php', 'cc_functions.php', 'theme.php' and 'xmldb.php'.
Mitigation:
Set 'register_globals' to 'off' and apply the latest patches.