Vulnerabilities > Postnuke Software Foundation > Postnuke > Medium

DATE CVE VULNERABILITY TITLE RISK
2007-01-19 CVE-2007-0384 Cross-Site Scripting vulnerability in Postnuke Software Foundation Postnuke 0.764
Cross-site scripting (XSS) vulnerability in preview in the reviews section in PostNuke 0.764 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
network
high complexity
postnuke-software-foundation
5.1
2006-02-20 CVE-2006-0801 Input Validation vulnerability in PostNuke
SQL injection vulnerability in the NS-Languages module for PostNuke 0.761 and earlier, when magic_quotes_gpc is off, allows remote attackers to execute arbitrary SQL commands via the language parameter to admin.php.
network
high complexity
postnuke-software-foundation
5.1
2005-05-24 CVE-2005-1699 Directory Traversal vulnerability in Postnuke Software Foundation Postnuke 0.760Rc3
Directory traversal vulnerability in pnadminapi.php in the Xanthia module in PostNuke 0.760-RC3 allows remote administrators to read arbitrary files via a ..
network
low complexity
postnuke-software-foundation
4.0
2005-05-16 CVE-2005-1621 Directory Traversal vulnerability in Postnuke
Directory traversal vulnerability in the pnModFunc function in pnMod.php for PostNuke 0.750 through 0.760rc4 allows remote attackers to read arbitrary files via a ..
network
low complexity
postnuke-software-foundation
5.0
2005-05-02 CVE-2005-1050 Information Disclosure vulnerability in Postnuke Software Foundation Postnuke 0.760Rc3
The modload op in the Reviews module for PostNuke 0.760-RC3 allows remote attackers to obtain sensitive information via an invalid id parameter, which reveals the path in a PHP error message.
network
low complexity
postnuke-software-foundation
5.0
2004-12-31 CVE-2004-2752 Cross-Site Scripting vulnerability in Postnuke Software Foundation Postnuke 0.726
Cross-site scripting (XSS) vulnerability in the Downloads module in PostNuke up to 0.726, and possibly later versions, allows remote attackers to inject arbitrary HTML and web script via the ttitle parameter in a viewdownloaddetails action.
4.3
2004-12-31 CVE-2004-2751 SQL Injection vulnerability in Postnuke Software Foundation Postnuke 0.722/0.723/0.726
SQL injection vulnerability in the members_list module in PostNuke 0.726, and possibly earlier, allows remote attackers to execute arbitrary SQL commands via the sortby parameter.
6.8
2004-04-21 CVE-2004-1956 Cross-Site Scripting And Path Disclosure vulnerability in Postnuke Software Foundation Postnuke 0.726
PostNuke 0.7.2.6 allows remote attackers to gain information via a direct HTTP request to files in the (1) includes/blocks directory, (2) pnadodb directory, (3) NS-NewUser module, (4) NS-Your_Account, (5) NS-LostPassword module, or (6) NS-User module which reveals the path to the web server in a PHP error message.
network
low complexity
postnuke-software-foundation
5.0
2003-12-31 CVE-2003-1537 Path Traversal vulnerability in Postnuke Software Foundation Postnuke
Directory traversal vulnerability in PostNuke 0.723 and earlier allows remote attackers to include arbitrary files named theme.php via the theme parameter to index.php.
network
low complexity
postnuke-software-foundation CWE-22
5.0
2002-07-03 CVE-2002-0535 Cross-site scripting vulnerabilities in PostBoard 2.0.1 and earlier allows remote attackers to execute script as other users via (1) an [IMG] tag when BBCode is enabled, or (2) in a topic title.
network
low complexity
postboard postnuke-software-foundation
5.0