7.5
CVSSv2

CVE-2001-1460

Published: 13/10/2001 Updated: 11/07/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in article.php in PostNuke 0.62 up to and including 0.64 allows remote malicious users to bypass authentication via the user parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

postnuke software foundation postnuke 0.64

postnuke software foundation postnuke 0.62

postnuke software foundation postnuke 0.63

Exploits

source: wwwsecurityfocuscom/bid/3435/info PostNuke, successor to PHPNuke, is a content management system written in PHP PostNuke versions 062 to 064 suffer from a vulnerability that allows a remote user to log-in as any user with known username and ID without authentication The problem lies in a failure to filter inappropriate charact ...