Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
postnuke postnuke vulnerabilities and exploits
(subscribe to this query)
510
VMScore
CVE-2002-0535
Cross-site scripting vulnerabilities in PostBoard 2.0.1 and previous versions allows remote malicious users to execute script as other users via (1) an [IMG] tag when BBCode is enabled, or (2) in a topic title.
Postboard Postboard 2.0
Postboard Postboard 2.0.1
Postnuke Software Foundation Postnuke 0.64
Postnuke Software Foundation Postnuke 0.71
Postnuke Software Foundation Postnuke 0.70
Postnuke Software Foundation Postnuke 0.703
2 EDB exploits
755
VMScore
CVE-2006-5733
Directory traversal vulnerability in error.php in PostNuke 0.763 and previous versions allows remote malicious users to include and execute arbitrary local files via a .. (dot dot) in the PNSVlang (PNSV lang) cookie, as demonstrated by injecting PHP sequences into an Apache HTTP ...
Postnuke Software Foundation Postnuke 0.762
Postnuke Software Foundation Postnuke
1 EDB exploit
668
VMScore
CVE-2005-0617
SQL injection vulnerability in dl-search.php in PostNuke 0.750 and 0.760-RC2 allows remote malicious users to execute arbitrary SQL commands via the show parameter.
Postnuke Software Foundation Postnuke 0.750
Postnuke Software Foundation Postnuke 0.760 Rc2
231
VMScore
CVE-2005-1696
Multiple cross-site scripting (XSS) vulnerabilities in PostNuke 0.750 and 0.760RC3 allow remote malicious users to inject arbitrary web script or HTML via the (1) skin or (2) paletteid parameter to demo.php in the Xanthia module, or (3) the serverName parameter to config.php in t...
Postnuke Software Foundation Postnuke 0.750
Postnuke Software Foundation Postnuke 0.760 Rc3
755
VMScore
CVE-2008-1591
The pnVarPrepForStore function in PostNuke 0.764 and previous versions skips input sanitization when magic_quotes_runtime is enabled, which allows remote malicious users to conduct SQL injection attacks and execute arbitrary SQL commands via input associated with server variables...
Postnuke Postnuke
1 EDB exploit
755
VMScore
CVE-2010-1713
SQL injection vulnerability in modules.php in PostNuke 0.764 allows remote malicious users to execute arbitrary SQL commands via the sid parameter in a News article modload action.
Postnuke Postnuke 0.764
1 EDB exploit
445
VMScore
CVE-2003-1537
Directory traversal vulnerability in PostNuke 0.723 and previous versions allows remote malicious users to include arbitrary files named theme.php via the theme parameter to index.php.
Postnuke Software Foundation Postnuke
231
VMScore
CVE-2006-0802
Cross-site scripting (XSS) vulnerability in the NS-Languages module for PostNuke 0.761 and previous versions, when magic_quotes_gpc is enabled, allows remote malicious users to inject arbitrary web script or HTML via the language parameter in a missing or translation operation.
Postnuke Software Foundation Postnuke
515
VMScore
CVE-2006-0801
SQL injection vulnerability in the NS-Languages module for PostNuke 0.761 and previous versions, when magic_quotes_gpc is off, allows remote malicious users to execute arbitrary SQL commands via the language parameter to admin.php.
Postnuke Software Foundation Postnuke
1 EDB exploit
668
VMScore
CVE-2005-1048
SQL injection vulnerability in modules.php in PostNuke 0.760 RC3 allows remote malicious users to execute arbitrary SQL statements via the sid parameter. NOTE: the vendor reports that they could not reproduce the issues for 760 RC3, or for .750.
Postnuke Software Foundation Postnuke 0.760 Rc3
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2020-4463
CVE-2024-29895
inject
CVE-2023-52689
CVE-2024-5049
CVE-2024-5051
privilege escalation
physical
CVE-2023-52676
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
NEXT »