First published: Sat Oct 13 2001(Updated: )
SQL injection vulnerability in article.php in PostNuke 0.62 through 0.64 allows remote attackers to bypass authentication via the user parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Postnuke Software Foundation Pnphpbb | =0.62 | |
Postnuke Software Foundation Pnphpbb | =0.63 | |
Postnuke Software Foundation Pnphpbb | =0.64 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2001-1460 has been classified with a high severity due to its potential for bypassing authentication.
To fix CVE-2001-1460, update your PostNuke installation to version 0.65 or later.
CVE-2001-1460 affects PostNuke versions 0.62, 0.63, and 0.64.
CVE-2001-1460 is an SQL injection vulnerability that allows remote attackers to manipulate database queries.
Yes, CVE-2001-1460 can be exploited remotely, allowing attackers to bypass authentication without local access.