Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
postnuke software foundation postnuke vulnerabilities and exploits
(subscribe to this query)
668
VMScore
CVE-2005-1048
SQL injection vulnerability in modules.php in PostNuke 0.760 RC3 allows remote malicious users to execute arbitrary SQL statements via the sid parameter. NOTE: the vendor reports that they could not reproduce the issues for 760 RC3, or for .750.
Postnuke Software Foundation Postnuke 0.760 Rc3
445
VMScore
CVE-2005-1050
The modload op in the Reviews module for PostNuke 0.760-RC3 allows remote malicious users to obtain sensitive information via an invalid id parameter, which reveals the path in a PHP error message.
Postnuke Software Foundation Postnuke 0.760 Rc3
694
VMScore
CVE-2007-0385
The faq section in PostNuke 0.764 allows remote malicious users to obtain sensitive information (the full path) via "unvalidated output" in FAQ/index.php, possibly involving an undefined id_cat variable.
Postnuke Software Foundation Postnuke 0.764
890
VMScore
CVE-2007-0386
Unspecified vulnerability in the rating section in PostNuke 0.764 has unknown impact and attack vectors, related to "an interesting bug."
Postnuke Software Foundation Postnuke 0.764
755
VMScore
CVE-2002-2015
PHP file inclusion vulnerability in user.php in PostNuke 0.703 allows remote malicious users to include arbitrary files and possibly execute code via the caselist parameter.
Postnuke Software Foundation Postnuke 0.703
1 EDB exploit
383
VMScore
CVE-2004-2752
Cross-site scripting (XSS) vulnerability in the Downloads module in PostNuke up to 0.726, and possibly later versions, allows remote malicious users to inject arbitrary HTML and web script via the ttitle parameter in a viewdownloaddetails action.
Postnuke Software Foundation Postnuke 0.726
270
VMScore
CVE-2005-2689
Multiple cross-site scripting (XSS) vulnerabilities in PostNuke 0.760-RC4b allows remote malicious users to inject arbitrary web script or HTML via (1) the moderate parameter to the Comments module or (2) htmltext parameter to html/user.php.
Postnuke Software Foundation Postnuke 0.76 Rc4b
2 EDB exploits
694
VMScore
CVE-2006-6267
PostNuke 0.7.5.0, and certain minor versions, allows remote malicious users to obtain sensitive information via a non-numeric value of the stop parameter, which reveals the path in an error message.
Postnuke Software Foundation Postnuke 0.7.5.0
668
VMScore
CVE-2005-1694
Multiple SQL injection vulnerabilities in Xanthia.php in the Xanthia module in PostNuke 0.750 allow remote malicious users to execute arbitrary SQL commands via the (1) name or (2) module parameter.
Postnuke Software Foundation Postnuke 0.750
356
VMScore
CVE-2005-1699
Directory traversal vulnerability in pnadminapi.php in the Xanthia module in PostNuke 0.760-RC3 allows remote administrators to read arbitrary files via a .. (dot dot) in the skin parameter.
Postnuke Software Foundation Postnuke 0.760 Rc3
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-25525
CVE-2024-4652
CVE-2024-1438
CVE-2024-4671
CVE-2024-34351
arbitrary
CVE-2024-4650
SQL injection
overflow
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
NEXT »