First published: Tue Apr 12 2005(Updated: )
SQL injection vulnerability in modules.php in PostNuke 0.760 RC3 allows remote attackers to execute arbitrary SQL statements via the sid parameter. NOTE: the vendor reports that they could not reproduce the issues for 760 RC3, or for .750.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Postnuke Software Foundation Pnphpbb | =0.760_rc3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-1048 is considered a high severity vulnerability due to its potential for remote SQL injection attacks.
CVE-2005-1048 occurs when the modules.php file in PostNuke 0.760 RC3 improperly handles the sid parameter, allowing attackers to execute arbitrary SQL statements.
CVE-2005-1048 affects users of PostNuke version 0.760 RC3 that have not applied relevant security patches.
Exploiting CVE-2005-1048 may allow attackers to gain unauthorized access to the database, leading to data leakage or manipulation.
To fix CVE-2005-1048, upgrade to a later version of PostNuke that has addressed this SQL injection vulnerability.