CVE-2007-5774 describes an information disclosure vulnerability in the File Manager module of Flatnuke 3. Remote attackers can exploit an invalid argumentname parameter in a 'disc op' action within index.php to trigger an error message revealing the full path of the application. This vulnerability has a CVSS score of 5.0, indicating a medium severity. It is easily exploitable over the network with low attack complexity and no authentication required, leading to a partial confidentiality impact by exposing sensitive system information. While not actively exploited in the wild (not in KEV), an ExploitDB entry (EDB-4561) suggests potential for remote command execution and privilege escalation, though this specific CVE only details information disclosure. There is no evidence of active exploitation, Metasploit modules, or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:flatnuke3:flatnuke3:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.