CVE-2001-1460: SQL Injection
Published Oct 13, 2001
·Updated
SQL injection vulnerability in article.php in PostNuke 0.62 through 0.64 allows remote attackers to bypass authentication via the user parameter.
Affected Software
3 affected components
Postnuke Software Foundation Postnuke=0.62
Postnuke Software Foundation Postnuke=0.63
Postnuke Software Foundation Postnuke=0.64
Remediation
Patch Available
Event History
Oct 13, 2001
CVE Published
04:00 AM
Apr 21, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2001-1460?
CVE-2001-1460 has been classified with a high severity due to its potential for bypassing authentication.
2
How do I fix CVE-2001-1460?
To fix CVE-2001-1460, update your PostNuke installation to version 0.65 or later.
3
Which versions of PostNuke are affected by CVE-2001-1460?
CVE-2001-1460 affects PostNuke versions 0.62, 0.63, and 0.64.
4
What type of vulnerability is CVE-2001-1460?
CVE-2001-1460 is an SQL injection vulnerability that allows remote attackers to manipulate database queries.
5
Can CVE-2001-1460 be exploited remotely?
Yes, CVE-2001-1460 can be exploited remotely, allowing attackers to bypass authentication without local access.