Vulnerabilities > Postnuke Software Foundation > Postnuke > 0.760.rc4

DATE CVE VULNERABILITY TITLE RISK
2006-12-02 CVE-2006-6233 SQL-Injection vulnerability in Postnuke
SQL injection vulnerability in the Downloads module for unknown versions of PostNuke allows remote attackers to execute arbitrary SQL commands via the lid parameter in a viewdownloaddetails operation.
network
low complexity
postnuke-software-foundation
7.5
2005-05-16 CVE-2005-1621 Directory Traversal vulnerability in Postnuke
Directory traversal vulnerability in the pnModFunc function in pnMod.php for PostNuke 0.750 through 0.760rc4 allows remote attackers to read arbitrary files via a ..
network
low complexity
postnuke-software-foundation
5.0