VendorsPostnuke Software Foundationpostnuke0.726
Vulnerabilities

Postnuke Software Foundation Postnuke 0.726

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2004-1949
SQL injection vulnerability in PostNuke 7.2.6 and earlier allows remote attackers to execute arbitrary SQL via (1) the sif parameter to index.php in the Comments module or (2) timezoneoffset parameter to changeinfo.php in the Your_Account module.
Published 2005-05-10 · Modified
7.5EPSS 0.020
CVE-2004-2751
SQL injection vulnerability in the members_list module in PostNuke 0.726, and possibly earlier, allows remote attackers to execute arbitrary SQL commands via the sortby parameter.
Published 2007-11-14 · Modified
6.8EPSS 0.014
CVE-2004-1956
PostNuke 0.7.2.6 allows remote attackers to gain information via a direct HTTP request to files in the (1) includes/blocks directory, (2) pnadodb directory, (3) NS-NewUser module, (4) NS-Your_Account, (5) NS-LostPassword module, or (6) NS-User module which reveals the path to the web server in a PHP error message.
Published 2005-05-10 · Modified
5.0EPSS 0.015
CVE-2004-2752
Cross-site scripting (XSS) vulnerability in the Downloads module in PostNuke up to 0.726, and possibly later versions, allows remote attackers to inject arbitrary HTML and web script via the ttitle parameter in a viewdownloaddetails action.
Published 2007-11-14 · Modified
4.3EPSS 0.010
CVE-2004-1957
Multiple cross-site scripting (XSS) vulnerabilities in PostNuke 0.726 allows remote attackers to inject arbitrary web script or HTML via the (1) lid and query parameters to the Downloads module, (2) query parameter to the Web_links module, or (3) hlpfile parameter to openwindow.php.
Published 2005-05-10 · Modified
2.62 PoCEPSS 0.046