Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
postnuke vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2005-1777
SQL injection vulnerability in readpmsg.php in PostNuke 0.750 allows remote malicious users to execute arbitrary SQL commands via the start parameter.
Postnuke Software Foundation Postnuke 0.750
1 EDB exploit
NA
CVE-2005-1049
Multiple cross-site scripting vulnerabilities in PostNuke 0.760-RC3 allow remote malicious users to inject arbitrary web script or HTML via the (1) module parameter to admin.php or (2) op parameter to user.php. NOTE: the vendor reports that certain issues could not be reproduced ...
Postnuke Software Foundation Postnuke 0.760 Rc3
2 EDB exploits
NA
CVE-2007-0384
Cross-site scripting (XSS) vulnerability in preview in the reviews section in PostNuke 0.764 allows remote malicious users to inject arbitrary web script or HTML via unspecified vectors.
Postnuke Software Foundation Postnuke 0.764
NA
CVE-2007-0385
The faq section in PostNuke 0.764 allows remote malicious users to obtain sensitive information (the full path) via "unvalidated output" in FAQ/index.php, possibly involving an undefined id_cat variable.
Postnuke Software Foundation Postnuke 0.764
NA
CVE-2007-0386
Unspecified vulnerability in the rating section in PostNuke 0.764 has unknown impact and attack vectors, related to "an interesting bug."
Postnuke Software Foundation Postnuke 0.764
NA
CVE-2005-2690
SQL injection vulnerability in the Downloads module in PostNuke 0.760-RC4b allows PostNuke administrators to execute arbitrary SQL commands via the show parameter to dl-viewdownload.php.
Postnuke Software Foundation Postnuke 0.76 Rc4b
1 EDB exploit
NA
CVE-2005-1700
SQL injection vulnerability in pnadmin.php in the Xanthia module in PostNuke 0.760-RC3 allows remote administrators to execute arbitrary SQL commands via the riga[0] parameter.
Postnuke Software Foundation Postnuke 0.760 Rc3
NA
CVE-2004-1949
SQL injection vulnerability in PostNuke 7.2.6 and previous versions allows remote malicious users to execute arbitrary SQL via (1) the sif parameter to index.php in the Comments module or (2) timezoneoffset parameter to changeinfo.php in the Your_Account module.
Postnuke Software Foundation Postnuke 0.726
NA
CVE-2004-1956
PostNuke 0.7.2.6 allows remote malicious users to gain information via a direct HTTP request to files in the (1) includes/blocks directory, (2) pnadodb directory, (3) NS-NewUser module, (4) NS-Your_Account, (5) NS-LostPassword module, or (6) NS-User module which reveals the path ...
Postnuke Software Foundation Postnuke 0.726
NA
CVE-2005-2689
Multiple cross-site scripting (XSS) vulnerabilities in PostNuke 0.760-RC4b allows remote malicious users to inject arbitrary web script or HTML via (1) the moderate parameter to the Comments module or (2) htmltext parameter to html/user.php.
Postnuke Software Foundation Postnuke 0.76 Rc4b
2 EDB exploits
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
inject
CVE-2024-34001
CVE-2024-37018
LFI
CVE-2024-1275
CVE-2024-1086
CSRF
CVE-2024-31030
CVE-2024-24919
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
NEXT »