📦

postnuke

Vendor: postnuke

Actively Exploited 0 CISA KEV List
PoC / Exploits 16 Code Available
Total RCEs 0 Remote Access
Total CVEs 234 Total Indexed
Avg. EPSS 2.42% Exploit Prob.
Latest CVE CVE-2010-1713 May 04

Security Vulnerability Index

Page 1 / 24
7.5 CVSS
CVE-2010-1713
Exploit Found

SQL injection vulnerability in modules.php in PostNuke 0.764 allows remote attackers to execute arbitrary SQL commands via the sid parameter in a News article modload action.

EPSS: 1.99%
7.5 CVSS
CVE-2009-0728
Exploit Found

SQL injection vulnerability in the My_eGallery module for MAXdev MDPro (MD-Pro) and Postnuke allows remote attackers to execute arbitrary SQL commands via the pid parameter in a showpic action to index.php.

EPSS: 0.95%
7.5 CVSS
CVE-2008-1591
Exploit Found

The pnVarPrepForStore function in PostNuke 0.764 and earlier skips input sanitization when magic_quotes_runtime is enabled, which allows remote attackers to conduct SQL injection attacks and execute arbitrary SQL commands via input associated with server variables, as demonstrated by the CLIENT_IP HTTP header (HTTP_CLIENT_IP variable).

EPSS: 0.97%
10.0 CVSS

Unspecified vulnerability in the rating section in PostNuke 0.764 has unknown impact and attack vectors, related to "an interesting bug."

EPSS: 1.45%
5.1 CVSS

Cross-site scripting (XSS) vulnerability in preview in the reviews section in PostNuke 0.764 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

EPSS: 1.18%
7.8 CVSS

The faq section in PostNuke 0.764 allows remote attackers to obtain sensitive information (the full path) via "unvalidated output" in FAQ/index.php, possibly involving an undefined id_cat variable.

EPSS: 1.47%
7.8 CVSS

PostNuke 0.7.5.0, and certain minor versions, allows remote attackers to obtain sensitive information via a non-numeric value of the stop parameter, which reveals the path in an error message.

EPSS: 1.35%
7.5 CVSS

SQL injection vulnerability in the Downloads module for unknown versions of PostNuke allows remote attackers to execute arbitrary SQL commands via the lid parameter in a viewdownloaddetails operation. NOTE: this issue might have been in the viewdownloaddetails function in dl-downloaddetails.php, but PostNuke 0.764 does not appear to have this issue.

EPSS: 1.10%
7.5 CVSS
CVE-2006-5733
Exploit Found

Directory traversal vulnerability in error.php in PostNuke 0.763 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the PNSVlang (PNSV lang) cookie, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by error.php.

EPSS: 2.98%
7.5 CVSS

SQL injection vulnerability in modules/Downloads/admin.php in the Admin section of PostNuke 0.762 allows remote attackers to execute arbitrary SQL commands via the hits parameter.

EPSS: 1.35%