20050527 PostNuke Critical SQL Injection and XSS 0.750=>xmailing list
http://marc.info/?l=bugtraq&m=111721364707520&w=2 CVE-2005-1777
PostNuke 0.750 - 'readpmsg.php' SQL Injection
Record summary
CVE-2005-1777 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.
Description
SQL injection vulnerability in readpmsg.php in PostNuke 0.750 allows remote attackers to execute arbitrary SQL commands via the start parameter.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBPostNuke 0.750 - 'readpmsg.php' SQL InjectionExploitDB exploitby K-C0d3rNot analyzed1 file
References
4news.postnuke.comConfirmation
http://news.postnuke.com/Article2691.html 1014066vdb entry
http://securitytracker.com/id?1014066 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2005-1777