PostNuke Downloads Module "hits" SQL Injection Vulnerability
Auteur Sujet
Post 
Résumé :

Description
PostNuke is an Open Source, open-development content management system (CMS). PostNuke is still undergoing development, but a large number of core functions are
now stabilizing and a complete API for third-party developers is now implemented. The PostNuke Development Team has been notified about a vulnerability in the
0.762 version of PostNuke. Version 0.800 (currently in development) is unaffected.

Severity
Less critical

Impact
Manipulation of data

Vulnerabilities
SQL Injection Vulnerability (when logged in as user with administrative privilages)

Credits
Omid (omid hackers ir)

http://community.postnuke.com/index...rticle&sid=2783

Données personnelles