Vulnerabilities > Postnuke Software Foundation > Postnuke > High

DATE CVE VULNERABILITY TITLE RISK
2007-01-19 CVE-2007-0385 Information Disclosure vulnerability in Postnuke Software Foundation Postnuke 0.764
The faq section in PostNuke 0.764 allows remote attackers to obtain sensitive information (the full path) via "unvalidated output" in FAQ/index.php, possibly involving an undefined id_cat variable.
network
low complexity
postnuke-software-foundation
7.8
2006-12-04 CVE-2006-6267 Information Disclosure vulnerability in Postnuke Software Foundation Postnuke 0.7.5.0
PostNuke 0.7.5.0, and certain minor versions, allows remote attackers to obtain sensitive information via a non-numeric value of the stop parameter, which reveals the path in an error message.
network
low complexity
postnuke-software-foundation
7.8
2006-12-02 CVE-2006-6233 SQL-Injection vulnerability in Postnuke
SQL injection vulnerability in the Downloads module for unknown versions of PostNuke allows remote attackers to execute arbitrary SQL commands via the lid parameter in a viewdownloaddetails operation.
network
low complexity
postnuke-software-foundation
7.5
2006-11-06 CVE-2006-5733 Local File Include vulnerability in Postnuke Software Foundation Postnuke 0.762
Directory traversal vulnerability in error.php in PostNuke 0.763 and earlier allows remote attackers to include and execute arbitrary local files via a ..
network
low complexity
postnuke-software-foundation
7.5
2006-10-03 CVE-2006-5121 SQL Injection vulnerability in Postnuke Software Foundation Postnuke 0.762
SQL injection vulnerability in modules/Downloads/admin.php in the Admin section of PostNuke 0.762 allows remote attackers to execute arbitrary SQL commands via the hits parameter.
network
low complexity
postnuke-software-foundation
7.5
2006-01-09 CVE-2006-0147 Remote Security vulnerability in Moodle
Dynamic code evaluation vulnerability in tests/tmssql.php test script in ADOdb for PHP before 4.70, as used in multiple products including (1) Mantis, (2) PostNuke, (3) Moodle, (4) Cacti, (5) Xaraya, (6) PhpOpenChat, possibly (7) MAXdev MD-Pro, and (8) Simplog, allows remote attackers to execute arbitrary PHP functions via the do parameter, which is saved in a variable that is then executed as a function, as demonstrated using phpinfo.
7.5
2005-08-24 CVE-2005-2690 SQL Injection vulnerability in Postnuke Software Foundation Postnuke 0.76Rc4B
SQL injection vulnerability in the Downloads module in PostNuke 0.760-RC4b allows PostNuke administrators to execute arbitrary SQL commands via the show parameter to dl-viewdownload.php.
network
low complexity
postnuke-software-foundation
7.5
2005-05-31 CVE-2005-1777 Unspecified vulnerability in Postnuke Software Foundation Postnuke 0.750
SQL injection vulnerability in readpmsg.php in PostNuke 0.750 allows remote attackers to execute arbitrary SQL commands via the start parameter.
network
low complexity
postnuke-software-foundation
7.5
2005-05-24 CVE-2005-1700 Unspecified vulnerability in Postnuke Software Foundation Postnuke 0.760Rc3
SQL injection vulnerability in pnadmin.php in the Xanthia module in PostNuke 0.760-RC3 allows remote administrators to execute arbitrary SQL commands via the riga[0] parameter.
network
low complexity
postnuke-software-foundation
7.5
2005-05-24 CVE-2005-1694 Unspecified vulnerability in Postnuke Software Foundation Postnuke 0.750
Multiple SQL injection vulnerabilities in Xanthia.php in the Xanthia module in PostNuke 0.750 allow remote attackers to execute arbitrary SQL commands via the (1) name or (2) module parameter.
network
low complexity
postnuke-software-foundation
7.5