First published: Wed Mar 02 2005(Updated: )
Multiple SQL injection vulnerabilities in (1) index.php, (2) modules.php, or (3) admin.php in PostNuke 0.760-RC2 allow remote attackers to execute arbitrary SQL code via the catid parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Postnuke Software Foundation Pnphpbb | =0.760_rc2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-0615 is considered a high severity vulnerability due to its potential to allow arbitrary SQL code execution.
To fix CVE-2005-0615, upgrade PostNuke to the latest version that addresses these SQL injection vulnerabilities.
CVE-2005-0615 affects PostNuke version 0.760-RC2.
The consequences of CVE-2005-0615 include the potential for attackers to gain unauthorized access and manipulate the database.
To determine if you are vulnerable to CVE-2005-0615, check if you are running PostNuke version 0.760-RC2 and review your application for SQL injection vulnerabilities.