CVE-2010-1713
- EPSS 1.99%
- Veröffentlicht 04.05.2010 16:00:35
- Zuletzt bearbeitet 16.06.2026 23:19:10
SQL injection vulnerability in modules.php in PostNuke 0.764 allows remote attackers to execute arbitrary SQL commands via the sid parameter in a News article modload action.
CVE-2008-1591
- EPSS 0.97%
- Veröffentlicht 31.03.2008 23:44:00
- Zuletzt bearbeitet 16.06.2026 22:52:02
The pnVarPrepForStore function in PostNuke 0.764 and earlier skips input sanitization when magic_quotes_runtime is enabled, which allows remote attackers to conduct SQL injection attacks and execute arbitrary SQL commands via input associated with se...
- EPSS 1.13%
- Veröffentlicht 24.05.2005 04:00:00
- Zuletzt bearbeitet 16.06.2026 22:13:31
The RSS module in PostNuke 0.750 and 0.760RC2 and RC3 allows remote attackers to obtain sensitive information via a direct request to simple_smarty.php, which reveals the path in an error message.
- EPSS 1.13%
- Veröffentlicht 24.05.2005 04:00:00
- Zuletzt bearbeitet 16.06.2026 22:13:31
PostNuke 0.750 and 0.760RC3 allows remote attackers to obtain sensitive information via a direct request to (1) theme.php or (2) Xanthia.php in the Xanthia module, (3) user.php, (4) thelang.php, (5) text.php, (6) html.php, (7) menu.php, (8) finclude....