Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
postnuke postnuke vulnerabilities and exploits
(subscribe to this query)
270
VMScore
CVE-2005-1049
Multiple cross-site scripting vulnerabilities in PostNuke 0.760-RC3 allow remote malicious users to inject arbitrary web script or HTML via the (1) module parameter to admin.php or (2) op parameter to user.php. NOTE: the vendor reports that certain issues could not be reproduced ...
Postnuke Software Foundation Postnuke 0.760 Rc3
2 EDB exploits
445
VMScore
CVE-2005-1050
The modload op in the Reviews module for PostNuke 0.760-RC3 allows remote malicious users to obtain sensitive information via an invalid id parameter, which reveals the path in a PHP error message.
Postnuke Software Foundation Postnuke 0.760 Rc3
270
VMScore
CVE-2005-2689
Multiple cross-site scripting (XSS) vulnerabilities in PostNuke 0.760-RC4b allows remote malicious users to inject arbitrary web script or HTML via (1) the moderate parameter to the Comments module or (2) htmltext parameter to html/user.php.
Postnuke Software Foundation Postnuke 0.76 Rc4b
2 EDB exploits
755
VMScore
CVE-2005-2690
SQL injection vulnerability in the Downloads module in PostNuke 0.760-RC4b allows PostNuke administrators to execute arbitrary SQL commands via the show parameter to dl-viewdownload.php.
Postnuke Software Foundation Postnuke 0.76 Rc4b
1 EDB exploit
668
VMScore
CVE-2006-5121
SQL injection vulnerability in modules/Downloads/admin.php in the Admin section of PostNuke 0.762 allows remote malicious users to execute arbitrary SQL commands via the hits parameter.
Postnuke Software Foundation Postnuke 0.762
383
VMScore
CVE-2004-2752
Cross-site scripting (XSS) vulnerability in the Downloads module in PostNuke up to 0.726, and possibly later versions, allows remote malicious users to inject arbitrary HTML and web script via the ttitle parameter in a viewdownloaddetails action.
Postnuke Software Foundation Postnuke 0.726
668
VMScore
CVE-2005-0615
Multiple SQL injection vulnerabilities in (1) index.php, (2) modules.php, or (3) admin.php in PostNuke 0.760-RC2 allow remote malicious users to execute arbitrary SQL code via the catid parameter.
Postnuke Software Foundation Postnuke 0.760 Rc2
755
VMScore
CVE-2002-2015
PHP file inclusion vulnerability in user.php in PostNuke 0.703 allows remote malicious users to include arbitrary files and possibly execute code via the caselist parameter.
Postnuke Software Foundation Postnuke 0.703
1 EDB exploit
454
VMScore
CVE-2007-0384
Cross-site scripting (XSS) vulnerability in preview in the reviews section in PostNuke 0.764 allows remote malicious users to inject arbitrary web script or HTML via unspecified vectors.
Postnuke Software Foundation Postnuke 0.764
694
VMScore
CVE-2007-0385
The faq section in PostNuke 0.764 allows remote malicious users to obtain sensitive information (the full path) via "unvalidated output" in FAQ/index.php, possibly involving an undefined id_cat variable.
Postnuke Software Foundation Postnuke 0.764
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2020-4463
CVE-2024-29895
inject
CVE-2023-52689
CVE-2024-5049
CVE-2024-5051
privilege escalation
physical
CVE-2023-52676
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
NEXT »