CVE-2005-2690

PostNuke <0.760-RC4b - SQL Injection

Title source: llm
STIX 2.1

Description

SQL injection vulnerability in the Downloads module in PostNuke 0.760-RC4b allows PostNuke administrators to execute arbitrary SQL commands via the show parameter to dl-viewdownload.php.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Maksymilian Arciemowicz · textwebappsphp
https://www.exploit-db.com/exploits/26189

References (2)

Core 2
Core References
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/14636
Exploit, Vendor Advisory mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/408818

Scores

EPSS 0.0027
EPSS Percentile 50.7%

Details

Status published
Products (1)
postnuke_software_foundation/postnuke 0.76_rc4b
Published Aug 24, 2005
Tracked Since Feb 18, 2026