CVE-2005-1694: SQL Injection
Published May 24, 2005
·Updated
Multiple SQL injection vulnerabilities in Xanthia.php in the Xanthia module in PostNuke 0.750 allow remote attackers to execute arbitrary SQL commands via the (1) name or (2) module parameter.
Affected Software
1 affected component
Postnuke Software Foundation Postnuke=0.750
Remediation
Event History
May 24, 2005
CVE Published
04:00 AM
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-1694?
CVE-2005-1694 is classified as a medium severity vulnerability due to its potential for SQL injection attacks.
2
How do I fix CVE-2005-1694?
To fix CVE-2005-1694, upgrade PostNuke to a version higher than 0.750 to eliminate the SQL injection vulnerabilities.
3
What applications are affected by CVE-2005-1694?
CVE-2005-1694 specifically affects PostNuke version 0.750.
4
Can CVE-2005-1694 be exploited remotely?
Yes, CVE-2005-1694 can be exploited by remote attackers to execute arbitrary SQL commands.
5
What are the parameters involved in CVE-2005-1694 exploit?
The parameters involved in the CVE-2005-1694 SQL injection exploit are 'name' and 'module'.