CVE-2010-1713: SQL Injection
Published May 4, 2010
·Updated
SQL injection vulnerability in modules.php in PostNuke 0.764 allows remote attackers to execute arbitrary SQL commands via the sid parameter in a News article modload action.
Affected Software
1 affected component
Postnuke Postnuke=0.764
Event History
May 4, 2010
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Data Sourced
via NVD·04:00 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2010-1713?
CVE-2010-1713 has a severity rating of high due to its ability to allow remote attackers to execute arbitrary SQL commands.
2
How do I fix CVE-2010-1713?
To fix CVE-2010-1713, upgrade to a version of PostNuke that is not vulnerable to this SQL injection issue.
3
What systems are affected by CVE-2010-1713?
CVE-2010-1713 specifically affects PostNuke version 0.764.
4
Can CVE-2010-1713 be exploited remotely?
Yes, CVE-2010-1713 can be exploited remotely by attackers through the sid parameter in a News article modload action.
5
What type of vulnerability is CVE-2010-1713 classified as?
CVE-2010-1713 is classified as an SQL injection vulnerability.