Skip to content
Noroxi

postnuke records

5 published records for vendor postnuke.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
3
With a fix record
0%
Median publish → KEV
No record has entered KEV

Records by year

    Bar: total · dark part: CISA KEV.

    All records

    5 records
    • CVE-2010-1713
      31Monitor

      SQL injection vulnerability in modules.php in PostNuke 0.764 allows remote attackers to execute arbitrary SQL commands via the sid parameter

      HighCVSS 7.5Proof of conceptEPSS 2%

      postnuke · postnukeMay 4, 2010

    • CVE-2008-1591
      30Monitor

      The pnVarPrepForStore function in PostNuke 0.764 and earlier skips input sanitization when magic_quotes_runtime is enabled, which allows rem

      HighCVSS 7.5Proof of conceptEPSS 1%

      postnuke · postnukeMar 31, 2008

    • CVE-2009-0728
      30Monitor

      SQL injection vulnerability in the My_eGallery module for MAXdev MDPro (MD-Pro) and Postnuke allows remote attackers to execute arbitrary SQ

      HighCVSS 7.5Proof of conceptEPSS 1%

      maxdev · my egalleryFeb 24, 2009

    • CVE-2005-1697
      20Monitor

      The RSS module in PostNuke 0.750 and 0.760RC2 and RC3 allows remote attackers to obtain sensitive information via a direct request to simple

      MediumCVSS 5.0No exploitEPSS 1%

      postnuke · postnukeMay 24, 2005

    • CVE-2005-1698
      20Monitor

      PostNuke 0.750 and 0.760RC3 allows remote attackers to obtain sensitive information via a direct request to (1) theme.php or (2) Xanthia.php

      MediumCVSS 5.0No exploitEPSS 1%

      postnuke · postnukeMay 24, 2005