Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
postnuke software foundation postnuke vulnerabilities and exploits
(subscribe to this query)
668
VMScore
CVE-2005-1700
SQL injection vulnerability in pnadmin.php in the Xanthia module in PostNuke 0.760-RC3 allows remote administrators to execute arbitrary SQL commands via the riga[0] parameter.
Postnuke Software Foundation Postnuke 0.760 Rc3
383
VMScore
CVE-2004-2752
Cross-site scripting (XSS) vulnerability in the Downloads module in PostNuke up to 0.726, and possibly later versions, allows remote malicious users to inject arbitrary HTML and web script via the ttitle parameter in a viewdownloaddetails action.
Postnuke Software Foundation Postnuke 0.726
270
VMScore
CVE-2005-2689
Multiple cross-site scripting (XSS) vulnerabilities in PostNuke 0.760-RC4b allows remote malicious users to inject arbitrary web script or HTML via (1) the moderate parameter to the Comments module or (2) htmltext parameter to html/user.php.
Postnuke Software Foundation Postnuke 0.76 Rc4b
2 EDB exploits
694
VMScore
CVE-2006-6267
PostNuke 0.7.5.0, and certain minor versions, allows remote malicious users to obtain sensitive information via a non-numeric value of the stop parameter, which reveals the path in an error message.
Postnuke Software Foundation Postnuke 0.7.5.0
668
VMScore
CVE-2005-1048
SQL injection vulnerability in modules.php in PostNuke 0.760 RC3 allows remote malicious users to execute arbitrary SQL statements via the sid parameter. NOTE: the vendor reports that they could not reproduce the issues for 760 RC3, or for .750.
Postnuke Software Foundation Postnuke 0.760 Rc3
445
VMScore
CVE-2005-1050
The modload op in the Reviews module for PostNuke 0.760-RC3 allows remote malicious users to obtain sensitive information via an invalid id parameter, which reveals the path in a PHP error message.
Postnuke Software Foundation Postnuke 0.760 Rc3
231
VMScore
CVE-2005-1778
Cross-site scripting (XSS) vulnerability in readpmsg.php in PostNuke 0.750 allows remote malicious users to inject arbitrary web script or HTML via the start parameter.
Postnuke Software Foundation Postnuke 0.750
668
VMScore
CVE-2005-1694
Multiple SQL injection vulnerabilities in Xanthia.php in the Xanthia module in PostNuke 0.750 allow remote malicious users to execute arbitrary SQL commands via the (1) name or (2) module parameter.
Postnuke Software Foundation Postnuke 0.750
668
VMScore
CVE-2006-5121
SQL injection vulnerability in modules/Downloads/admin.php in the Admin section of PostNuke 0.762 allows remote malicious users to execute arbitrary SQL commands via the hits parameter.
Postnuke Software Foundation Postnuke 0.762
668
VMScore
CVE-2004-1949
SQL injection vulnerability in PostNuke 7.2.6 and previous versions allows remote malicious users to execute arbitrary SQL via (1) the sif parameter to index.php in the Comments module or (2) timezoneoffset parameter to changeinfo.php in the Your_Account module.
Postnuke Software Foundation Postnuke 0.726
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
spoof
CVE-2024-34928
CVE-2024-5291
deserialization
CVE-2024-4471
CVE-2024-4956
CVE-2024-32002
CVE-2024-5227
unspecified
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
NEXT »