Vulnerabilities > CVE-2006-0801 - Unspecified vulnerability in Postnuke Software Foundation Postnuke
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
SQL injection vulnerability in the NS-Languages module for PostNuke 0.761 and earlier, when magic_quotes_gpc is off, allows remote attackers to execute arbitrary SQL commands via the language parameter to admin.php.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description | PostNuke 0.6x/0.7x NS-Languages Module language Parameter SQL Injection. CVE-2006-0801 . Webapps exploit for php platform |
id | EDB-ID:27255 |
last seen | 2016-02-03 |
modified | 2006-02-21 |
published | 2006-02-21 |
reporter | Maksymilian Arciemowicz |
source | https://www.exploit-db.com/download/27255/ |
title | PostNuke 0.6x/0.7x NS-Languages Module language Parameter SQL Injection |
Nessus
NASL family | CGI abuses |
NASL id | POSTNUKE_0_762.NASL |
description | The installed version of PostNuke allows an unauthenticated attacker to gain administrative access to select modules through a simple GET request. Additionally, it may be prone to various SQL injection injection or cross-site scripting attacks as well as unspecified attacks through the Languages module. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 20969 |
published | 2006-02-22 |
reporter | This script is Copyright (C) 2006-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/20969 |
title | PostNuke < 0.762 Multiple Vulnerabilities |
code |
|
References
- http://archives.neohapsis.com/archives/fulldisclosure/2006-02/0469.html
- http://news.postnuke.com/index.php?name=News&file=article&sid=2754
- http://www.securityfocus.com/bid/16752
- http://secunia.com/advisories/18937
- http://www.vupen.com/english/advisories/2006/0673
- http://securityreason.com/securityalert/454
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24827