header-logo
Suggest Exploit
vendor:
Flatnux
by:
SecurityFocus
7,5
CVSS
HIGH
HTML-injection, Cross-site Request-Forgery, Directory-Traversal
79, 352, 22
CWE
Product Name: Flatnux
Affected Version From: Flatnux 2011-08.09.2
Affected Version To: Fncommerce 2010-12-17-with-sample-data
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2011

Multiple Security Vulnerabilities in Flatnux

Flatnux is prone to multiple security vulnerabilities, including HTML-injection, cross-site request-forgery, and directory-traversal vulnerabilities. Successful exploits will allow attacker-supplied HTML and script code to run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials, obtain sensitive information, or control how the site is rendered to the user. Other attacks are also possible.

Mitigation:

Users should apply the latest available updates to Flatnux, and should also ensure that all web browsers and other applications are kept up-to-date.
Source

Exploit-DB raw data:

source: https://www.securityfocus.com/bid/52846/info

Flatnux is prone to multiple security vulnerabilities:

1. An HTML-injection vulnerability
2. A cross-site request-forgery vulnerability
3. A directory-traversal vulnerability

Successful exploits will allow attacker-supplied HTML and script code to run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials, obtain sensitive information, or control how the site is rendered to the user. Other attacks are also possible.

The following versions are vulnerable:

Flatnux 2011-08.09.2
Flatnux 2011-2012-01.03.3
Flatnux 2011-minimal-2012-01.03.3
Fncommerce 2010-08-09-no-db
Fncommerce 2010-08-09-no-sample-data
Fncommerce 2010-08-09-with-sample-data
Fncommerce 2010-12-17-no-db
Fncommerce 2010-12-17-no-sample-data
Fncommerce 2010-12-17-with-sample-data 

http://www.example.com/flatnux/controlcenter.php?opt=contents/Files&dir=%2Fetc&ffile=passwd&opmod=open