First published: Sat Dec 02 2006(Updated: )
SQL injection vulnerability in the Downloads module for unknown versions of PostNuke allows remote attackers to execute arbitrary SQL commands via the lid parameter in a viewdownloaddetails operation. NOTE: this issue might have been in the viewdownloaddetails function in dl-downloaddetails.php, but PostNuke 0.764 does not appear to have this issue.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Postnuke Software Foundation Postnuke | =0.761 | |
Postnuke Software Foundation Postnuke | =0.760_rc4 | |
Postnuke Software Foundation Postnuke | =0.760_rc3 | |
Postnuke Software Foundation Postnuke | =0.760_rc2 | |
Postnuke Software Foundation Postnuke | =0.762 | |
Postnuke Software Foundation Postnuke | =0.763 | |
Postnuke Software Foundation Postnuke | =0.76_rc4b | |
Postnuke Software Foundation Postnuke | =0.76_rc4 | |
Postnuke Software Foundation Postnuke | =0.761a | |
Postnuke Software Foundation Postnuke | =0.76_rc4a |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.