CVE-2006-0801: SQL Injection
Published Feb 20, 2006
·Updated
SQL injection vulnerability in the NS-Languages module for PostNuke 0.761 and earlier, when magicquotesgpc is off, allows remote attackers to execute arbitrary SQL commands via the language parameter to admin.php.
Affected Software
1 affected component
Postnuke Software Foundation Postnuke<=0.761
Remediation
Patch Available
Patch Available
Event History
Feb 20, 2006
CVE Published
10:02 PM
Feb 21, 2006
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-0801?
CVE-2006-0801 has a medium severity rating due to the potential for remote SQL execution leading to data compromise.
2
How do I fix CVE-2006-0801?
To fix CVE-2006-0801, update PostNuke to a version later than 0.761 or ensure that magic_quotes_gpc is enabled.
3
Who is affected by CVE-2006-0801?
All users of PostNuke version 0.761 and earlier are affected by CVE-2006-0801.
4
What type of vulnerability is CVE-2006-0801?
CVE-2006-0801 is an SQL injection vulnerability that allows attackers to execute arbitrary SQL commands.
5
When was CVE-2006-0801 disclosed?
CVE-2006-0801 was disclosed in February 2006.