Vulnerabilities > Postnuke Software Foundation > Postnuke > High
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2007-01-19 | CVE-2007-0385 | Information Disclosure vulnerability in Postnuke Software Foundation Postnuke 0.764 The faq section in PostNuke 0.764 allows remote attackers to obtain sensitive information (the full path) via "unvalidated output" in FAQ/index.php, possibly involving an undefined id_cat variable. | 7.8 |
2006-12-04 | CVE-2006-6267 | Information Disclosure vulnerability in Postnuke Software Foundation Postnuke 0.7.5.0 PostNuke 0.7.5.0, and certain minor versions, allows remote attackers to obtain sensitive information via a non-numeric value of the stop parameter, which reveals the path in an error message. | 7.8 |
2006-12-02 | CVE-2006-6233 | SQL-Injection vulnerability in Postnuke SQL injection vulnerability in the Downloads module for unknown versions of PostNuke allows remote attackers to execute arbitrary SQL commands via the lid parameter in a viewdownloaddetails operation. | 7.5 |
2006-11-06 | CVE-2006-5733 | Local File Include vulnerability in Postnuke Software Foundation Postnuke 0.762 Directory traversal vulnerability in error.php in PostNuke 0.763 and earlier allows remote attackers to include and execute arbitrary local files via a .. | 7.5 |
2006-10-03 | CVE-2006-5121 | SQL Injection vulnerability in Postnuke Software Foundation Postnuke 0.762 SQL injection vulnerability in modules/Downloads/admin.php in the Admin section of PostNuke 0.762 allows remote attackers to execute arbitrary SQL commands via the hits parameter. | 7.5 |
2006-01-09 | CVE-2006-0147 | Remote Security vulnerability in Moodle Dynamic code evaluation vulnerability in tests/tmssql.php test script in ADOdb for PHP before 4.70, as used in multiple products including (1) Mantis, (2) PostNuke, (3) Moodle, (4) Cacti, (5) Xaraya, (6) PhpOpenChat, possibly (7) MAXdev MD-Pro, and (8) Simplog, allows remote attackers to execute arbitrary PHP functions via the do parameter, which is saved in a variable that is then executed as a function, as demonstrated using phpinfo. | 7.5 |
2005-08-24 | CVE-2005-2690 | SQL Injection vulnerability in Postnuke Software Foundation Postnuke 0.76Rc4B SQL injection vulnerability in the Downloads module in PostNuke 0.760-RC4b allows PostNuke administrators to execute arbitrary SQL commands via the show parameter to dl-viewdownload.php. | 7.5 |
2005-05-31 | CVE-2005-1777 | Unspecified vulnerability in Postnuke Software Foundation Postnuke 0.750 SQL injection vulnerability in readpmsg.php in PostNuke 0.750 allows remote attackers to execute arbitrary SQL commands via the start parameter. | 7.5 |
2005-05-24 | CVE-2005-1700 | Unspecified vulnerability in Postnuke Software Foundation Postnuke 0.760Rc3 SQL injection vulnerability in pnadmin.php in the Xanthia module in PostNuke 0.760-RC3 allows remote administrators to execute arbitrary SQL commands via the riga[0] parameter. | 7.5 |
2005-05-24 | CVE-2005-1694 | Unspecified vulnerability in Postnuke Software Foundation Postnuke 0.750 Multiple SQL injection vulnerabilities in Xanthia.php in the Xanthia module in PostNuke 0.750 allow remote attackers to execute arbitrary SQL commands via the (1) name or (2) module parameter. | 7.5 |