Postnuke

Postnuke Software Foundation · 42 CVEs

CVE-2010-1713
HIGH

SQL injection vulnerability in modules.php in PostNuke 0.764 allows remote attackers to execute arbitrary SQL commands…

May 4, 2010

CVE-2008-1591
HIGH

The pnVarPrepForStore function in PostNuke 0.764 and earlier skips input sanitization when magic_quotes_runtime is enab…

Mar 31, 2008

CVE-2004-2752
MEDIUM

Cross-site scripting (XSS) vulnerability in the Downloads module in PostNuke up to 0.726, and possibly later versions,…

Nov 14, 2007

CVE-2004-2751
MEDIUM

SQL injection vulnerability in the members_list module in PostNuke 0.726, and possibly earlier, allows remote attackers…

Nov 14, 2007

CVE-2003-1537
MEDIUM

Directory traversal vulnerability in PostNuke 0.723 and earlier allows remote attackers to include arbitrary files name…

Nov 14, 2007

CVE-2007-0386
HIGH

Unspecified vulnerability in the rating section in PostNuke 0.764 has unknown impact and attack vectors, related to "an…

Jan 19, 2007

CVE-2007-0385
HIGH

The faq section in PostNuke 0.764 allows remote attackers to obtain sensitive information (the full path) via "unvalida…

Jan 19, 2007

CVE-2007-0384
MEDIUM

Cross-site scripting (XSS) vulnerability in preview in the reviews section in PostNuke 0.764 allows remote attackers to…

Jan 19, 2007

CVE-2006-6267
HIGH

PostNuke 0.7.5.0, and certain minor versions, allows remote attackers to obtain sensitive information via a non-numeric…

Dec 4, 2006

CVE-2006-6233
HIGH

SQL injection vulnerability in the Downloads module for unknown versions of PostNuke allows remote attackers to execute…

Dec 2, 2006

CVE-2006-5733
HIGH

Directory traversal vulnerability in error.php in PostNuke 0.763 and earlier allows remote attackers to include and exe…

Nov 6, 2006

CVE-2006-5121
HIGH

SQL injection vulnerability in modules/Downloads/admin.php in the Admin section of PostNuke 0.762 allows remote attacke…

Oct 2, 2006

CVE-2006-0802
LOW

Cross-site scripting (XSS) vulnerability in the NS-Languages module for PostNuke 0.761 and earlier, when magic_quotes_g…

Feb 20, 2006

CVE-2006-0801
MEDIUM

SQL injection vulnerability in the NS-Languages module for PostNuke 0.761 and earlier, when magic_quotes_gpc is off, al…

Feb 20, 2006

CVE-2006-0800
LOW

Interpretation conflict in PostNuke 0.761 and earlier allows remote attackers to conduct cross-site scripting (XSS) att…

Feb 20, 2006

CVE-2006-0147
HIGH

Dynamic code evaluation vulnerability in tests/tmssql.php test script in ADOdb for PHP before 4.70, as used in multiple…

Jan 9, 2006

CVE-2006-0146
HIGH

The server.php test script in ADOdb for PHP before 4.70, as used in multiple products including (1) Mantis, (2) PostNuk…

Jan 9, 2006

CVE-2005-2690
HIGH

SQL injection vulnerability in the Downloads module in PostNuke 0.760-RC4b allows PostNuke administrators to execute ar…

Aug 24, 2005

CVE-2005-2689
LOW

Multiple cross-site scripting (XSS) vulnerabilities in PostNuke 0.760-RC4b allows remote attackers to inject arbitrary…

Aug 24, 2005

CVE-2002-2015
HIGH

PHP file inclusion vulnerability in user.php in PostNuke 0.703 allows remote attackers to include arbitrary files and p…

Jul 14, 2005

CVE-2002-1996
LOW

Cross-site scripting (XSS) vulnerability in PostNuke 0.71 and earlier allows remote attackers to inject arbitrary web s…

Jul 14, 2005

CVE-2001-1521
LOW

Cross-site scripting (XSS) vulnerability in user.php in PostNuke 0.64 allows remote attackers to inject arbitrary web s…

Jul 14, 2005

CVE-2005-1778
LOW

Cross-site scripting (XSS) vulnerability in readpmsg.php in PostNuke 0.750 allows remote attackers to inject arbitrary…

May 31, 2005

CVE-2005-1777
HIGH

SQL injection vulnerability in readpmsg.php in PostNuke 0.750 allows remote attackers to execute arbitrary SQL commands…

May 31, 2005

CVE-2005-1700
HIGH

SQL injection vulnerability in pnadmin.php in the Xanthia module in PostNuke 0.760-RC3 allows remote administrators to…

May 24, 2005

Showing 1 to 25 of 42 CVEs