vendor:
Flatnuke3
by:
7.5
CVSS
HIGH
Unauthorized Access
287
CWE
Product Name: Flatnuke3
Affected Version From: Flatnuke3-2007-10-10
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
Unauthorized Access Vulnerability in Flatnuke3
Flatnuke3 is prone to an unauthorized-access vulnerability because it fails to adequately verify administrative credentials while logging in via the 'File Manager' module. An attacker can exploit this vulnerability to gain administrative control of the application; other attacks are also possible.
Mitigation:
Update to the latest version of Flatnuke3 or apply the appropriate patch provided by the vendor.