Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
postnuke software foundation postnuke 0.726 vulnerabilities and exploits
(subscribe to this query)
6.8
CVSSv2
CVE-2004-2751
SQL injection vulnerability in the members_list module in PostNuke 0.726, and possibly earlier, allows remote malicious users to execute arbitrary SQL commands via the sortby parameter.
Postnuke Software Foundation Postnuke 0.722
Postnuke Software Foundation Postnuke 0.723
Postnuke Software Foundation Postnuke 0.726
4.3
CVSSv2
CVE-2004-2752
Cross-site scripting (XSS) vulnerability in the Downloads module in PostNuke up to 0.726, and possibly later versions, allows remote malicious users to inject arbitrary HTML and web script via the ttitle parameter in a viewdownloaddetails action.
Postnuke Software Foundation Postnuke 0.726
7.5
CVSSv2
CVE-2004-1949
SQL injection vulnerability in PostNuke 7.2.6 and previous versions allows remote malicious users to execute arbitrary SQL via (1) the sif parameter to index.php in the Comments module or (2) timezoneoffset parameter to changeinfo.php in the Your_Account module.
Postnuke Software Foundation Postnuke 0.726
5
CVSSv2
CVE-2004-1956
PostNuke 0.7.2.6 allows remote malicious users to gain information via a direct HTTP request to files in the (1) includes/blocks directory, (2) pnadodb directory, (3) NS-NewUser module, (4) NS-Your_Account, (5) NS-LostPassword module, or (6) NS-User module which reveals the path ...
Postnuke Software Foundation Postnuke 0.726
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2022-48693
CVE-2024-30851
CVE-2024-34460
CVE-2024-2887
local
CVE-2024-27956
remote code execution
CVE-2024-34475
privilege
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started