Записи postnuke
5 опубликованных записей вендора postnuke.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 3
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Записи по годам
Столбик: всего · тёмная часть: CISA KEV.
Повторяющиеся классы
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')3
- CWE-425 Direct Request ('Forced Browsing')2
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEПрофиль атаки
Все записи
5 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
31Наблюдать | CVE-2010-1713Proof of concept | SQL injection vulnerability in modules.php in PostNuke 0.764 allows remote attackers to execute arbitrary SQL commands via the sid parameterpostnuke · postnuke · CWE-89 | Высокая7,5 | — | 2,0 % | 4 мая 2010 г. |
30Наблюдать | CVE-2008-1591Proof of concept | The pnVarPrepForStore function in PostNuke 0.764 and earlier skips input sanitization when magic_quotes_runtime is enabled, which allows rempostnuke · postnuke · CWE-89 | Высокая7,5 | — | 1,0 % | 31 мар. 2008 г. |
30Наблюдать | CVE-2009-0728Proof of concept | SQL injection vulnerability in the My_eGallery module for MAXdev MDPro (MD-Pro) and Postnuke allows remote attackers to execute arbitrary SQmaxdev · my egallery · CWE-89 | Высокая7,5 | — | 1,0 % | 24 февр. 2009 г. |
20Наблюдать | CVE-2005-1697Эксплойта нет | The RSS module in PostNuke 0.750 and 0.760RC2 and RC3 allows remote attackers to obtain sensitive information via a direct request to simplepostnuke · postnuke · CWE-425 | Средняя5,0 | — | 1,1 % | 24 мая 2005 г. |
20Наблюдать | CVE-2005-1698Эксплойта нет | PostNuke 0.750 and 0.760RC3 allows remote attackers to obtain sensitive information via a direct request to (1) theme.php or (2) Xanthia.phppostnuke · postnuke · CWE-425 | Средняя5,0 | — | 1,1 % | 24 мая 2005 г. |
- CVE-2010-171331Наблюдать
SQL injection vulnerability in modules.php in PostNuke 0.764 allows remote attackers to execute arbitrary SQL commands via the sid parameter
ВысокаяCVSS 7,5Proof of conceptEPSS 2 %postnuke · postnuke4 мая 2010 г.
- CVE-2008-159130Наблюдать
The pnVarPrepForStore function in PostNuke 0.764 and earlier skips input sanitization when magic_quotes_runtime is enabled, which allows rem
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %postnuke · postnuke31 мар. 2008 г.
- CVE-2009-072830Наблюдать
SQL injection vulnerability in the My_eGallery module for MAXdev MDPro (MD-Pro) and Postnuke allows remote attackers to execute arbitrary SQ
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %maxdev · my egallery24 февр. 2009 г.
- CVE-2005-169720Наблюдать
The RSS module in PostNuke 0.750 and 0.760RC2 and RC3 allows remote attackers to obtain sensitive information via a direct request to simple
СредняяCVSS 5,0Эксплойта нетEPSS 1 %postnuke · postnuke24 мая 2005 г.
- CVE-2005-169820Наблюдать
PostNuke 0.750 and 0.760RC3 allows remote attackers to obtain sensitive information via a direct request to (1) theme.php or (2) Xanthia.php
СредняяCVSS 5,0Эксплойта нетEPSS 1 %postnuke · postnuke24 мая 2005 г.