SQL injection vulnerability in the members_list module in PostNuke 0.726, and possibly earlier, allows remote malicious users to execute arbitrary SQL commands via the sortby parameter.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
postnuke software foundation postnuke 0.722 |
||
postnuke software foundation postnuke 0.723 |
||
postnuke software foundation postnuke 0.726 |