Postnuke 0.760 Release Candidate 3

CPE Details

Postnuke 0.760 Release Candidate 3
0.760
2023-12-28
15h46 +00:00
2023-12-28
15h46 +00:00
Alerte pour un CPE
Restez informé de toutes modifications pour un CPE spécifique.
Gestion des notifications

CPE Name: cpe:2.3:a:postnuke:postnuke:0.760:rc3:*:*:*:*:*:*

Informations

Vendor

postnuke

Product

postnuke

Version

0.760

Update

rc3

Related CVE

Open and find in CVE List

CVE ID Publié Description Score Gravité
CVE-2009-0728 2009-02-24 22h00 +00:00 SQL injection vulnerability in the My_eGallery module for MAXdev MDPro (MD-Pro) and Postnuke allows remote attackers to execute arbitrary SQL commands via the pid parameter in a showpic action to index.php.
7.5
CVE-2008-1591 2008-03-31 21h00 +00:00 The pnVarPrepForStore function in PostNuke 0.764 and earlier skips input sanitization when magic_quotes_runtime is enabled, which allows remote attackers to conduct SQL injection attacks and execute arbitrary SQL commands via input associated with server variables, as demonstrated by the CLIENT_IP HTTP header (HTTP_CLIENT_IP variable).
7.5
CVE-2005-1697 2005-05-24 02h00 +00:00 The RSS module in PostNuke 0.750 and 0.760RC2 and RC3 allows remote attackers to obtain sensitive information via a direct request to simple_smarty.php, which reveals the path in an error message.
5
CVE-2005-1698 2005-05-24 02h00 +00:00 PostNuke 0.750 and 0.760RC3 allows remote attackers to obtain sensitive information via a direct request to (1) theme.php or (2) Xanthia.php in the Xanthia module, (3) user.php, (4) thelang.php, (5) text.php, (6) html.php, (7) menu.php, (8) finclude.php, or (9) button.php in the pnblocks directory in the Blocks module, (10) config.php in the NS-Multisites (aka Multisites) module, or (11) xmlrpc.php, which reveals the path in an error message.
5