CVE-2006-6233: SQL Injection
Published Dec 2, 2006
·Updated
SQL injection vulnerability in the Downloads module for unknown versions of PostNuke allows remote attackers to execute arbitrary SQL commands via the lid parameter in a viewdownloaddetails operation. NOTE: this issue might have been in the viewdownloaddetails function in dl-downloaddetails.php, but PostNuke 0.764 does not appear to have this issue.
Affected Software
10 affected components
Postnuke Software Foundation Postnuke=0.76_rc4
Postnuke Software Foundation Postnuke=0.76_rc4a
Postnuke Software Foundation Postnuke=0.76_rc4b
Postnuke Software Foundation Postnuke=0.760_rc2
Postnuke Software Foundation Postnuke=0.760_rc3
Postnuke Software Foundation Postnuke=0.760_rc4
Postnuke Software Foundation Postnuke=0.761
Postnuke Software Foundation Postnuke=0.761a
Postnuke Software Foundation Postnuke=0.762
Postnuke Software Foundation Postnuke=0.763
Event History
Dec 2, 2006
CVE Published
11:28 AM
Data Sourced
via NVD·11:28 AM
DescriptionSeverityAffected Software
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
Can I exploit CVE-2006-6233 to access sensitive data?
Yes, exploiting CVE-2006-6233 could allow an attacker to access sensitive data through arbitrary SQL commands.