Vulnerabilities > Postnuke Software Foundation > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2004-04-21 | CVE-2004-1956 | Cross-Site Scripting And Path Disclosure vulnerability in Postnuke Software Foundation Postnuke 0.726 PostNuke 0.7.2.6 allows remote attackers to gain information via a direct HTTP request to files in the (1) includes/blocks directory, (2) pnadodb directory, (3) NS-NewUser module, (4) NS-Your_Account, (5) NS-LostPassword module, or (6) NS-User module which reveals the path to the web server in a PHP error message. | 5.0 |
2003-12-31 | CVE-2003-1537 | Path Traversal vulnerability in Postnuke Software Foundation Postnuke Directory traversal vulnerability in PostNuke 0.723 and earlier allows remote attackers to include arbitrary files named theme.php via the theme parameter to index.php. | 5.0 |
2002-07-03 | CVE-2002-0535 | Cross-site scripting vulnerabilities in PostBoard 2.0.1 and earlier allows remote attackers to execute script as other users via (1) an [IMG] tag when BBCode is enabled, or (2) in a topic title. | 5.0 |