CVE-2005-0617: SQL Injection
Published Mar 2, 2005
·Updated
SQL injection vulnerability in dl-search.php in PostNuke 0.750 and 0.760-RC2 allows remote attackers to execute arbitrary SQL commands via the show parameter.
Affected Software
2 affected components
Postnuke Software Foundation Postnuke=0.760_rc2
Postnuke Software Foundation Postnuke=0.750
Remediation
Patch Available
Patch Available
Event History
Mar 2, 2005
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-0617?
CVE-2005-0617 is considered a critical vulnerability due to its potential for remote code execution via SQL injection.
2
How do I fix CVE-2005-0617?
To fix CVE-2005-0617, upgrade to a secured version of PostNuke that does not contain this vulnerability.
3
Which versions of PostNuke are affected by CVE-2005-0617?
CVE-2005-0617 affects PostNuke versions 0.750 and 0.760-RC2.
4
Can CVE-2005-0617 be exploited remotely?
Yes, CVE-2005-0617 allows remote attackers to exploit the vulnerability through the show parameter.
5
What type of vulnerability is CVE-2005-0617?
CVE-2005-0617 is categorized as an SQL injection vulnerability.