PostNuke Security Advisory 2006-1
Auteur Sujet
Post 
Résumé :

Arbitrary SQL code execution via adodb (when db-user is 'root' without password)

DESCRIPTION
PostNuke is an Open Source, open-development content management system (CMS). PostNuke is still undergoing development, but a large number of core functions are now stabilizing and a complete API for third-party developers is now implemented. The PostNuke CMS Development Team was notified by secunia.com about a vulnerability in the adodb database abstraction layer.



http://news.postnuke.com/index.php?...rticle&sid=2747

Données personnelles