Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
postnuke software foundation postnuke vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2008-2191
SQL injection vulnerability in the pnEncyclopedia module 0.2.0 and previous versions for PostNuke allows remote malicious users to execute arbitrary SQL commands via the id parameter in a display_term action to index.php.
Postnuke Software Foundation Pnencyclopedia
1 EDB exploit
NA
CVE-2008-2012
SQL injection vulnerability in index.php in the PostSchedule 1.0 module for PostNuke allows remote malicious users to execute arbitrary SQL commands via the eid parameter in an event action.
Postnuke Software Foundation Postschedule 1.0
1 EDB exploit
NA
CVE-2007-3584
SQL injection vulnerability in viewforum.php in PNphpBB2 1.2i and previous versions for Postnuke allows remote malicious users to execute arbitrary SQL commands via the order parameter.
Postnuke Software Foundation Pnphpbb2
1 EDB exploit
NA
CVE-2007-3052
SQL injection vulnerability in index.php in the PNphpBB2 1.2i and previous versions module for PostNuke allows remote malicious users to execute arbitrary SQL commands via the c parameter.
Postnuke Software Foundation Pnphpbb
1 EDB exploit
NA
CVE-2007-2492
SQL injection vulnerability in index.php in the v4bJournal module for PostNuke allows remote authenticated users to execute arbitrary SQL commands via the id parameter in a journal_comment action.
Postnuke Software Foundation Postnuke V4bjournal Module 0.99
1 EDB exploit
NA
CVE-2007-1158
Directory traversal vulnerability in index.php in the Pagesetter 6.2.0 up to and including 6.3.0 beta 5 module for PostNuke allows remote malicious users to read arbitrary files via a .. (dot dot) in the id parameter.
Postnuke Software Foundation Pagesetter 6.3.0
Postnuke Software Foundation Pagesetter 6.2
1 EDB exploit
NA
CVE-2007-0384
Cross-site scripting (XSS) vulnerability in preview in the reviews section in PostNuke 0.764 allows remote malicious users to inject arbitrary web script or HTML via unspecified vectors.
Postnuke Software Foundation Postnuke 0.764
NA
CVE-2007-0386
Unspecified vulnerability in the rating section in PostNuke 0.764 has unknown impact and attack vectors, related to "an interesting bug."
Postnuke Software Foundation Postnuke 0.764
NA
CVE-2007-0385
The faq section in PostNuke 0.764 allows remote malicious users to obtain sensitive information (the full path) via "unvalidated output" in FAQ/index.php, possibly involving an undefined id_cat variable.
Postnuke Software Foundation Postnuke 0.764
NA
CVE-2006-6267
PostNuke 0.7.5.0, and certain minor versions, allows remote malicious users to obtain sensitive information via a non-numeric value of the stop parameter, which reveals the path in an error message.
Postnuke Software Foundation Postnuke 0.7.5.0
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-33572
CVE-2024-24919
CVE-2024-0230
CVE-2024-32714
HTML injection
local file inclusion
CVE-2024-31098
CVE-2024-31244
privilege
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
4
5
NEXT »