CVE-2004-1949
N/A
N/A
Summary
SQL injection vulnerability in PostNuke 7.2.6 and earlier allows remote attackers to execute arbitrary SQL via (1) the sif parameter to index.php in the Comments module or (2) timezoneoffset parameter to changeinfo.php in the Your_Account module.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| n/a | n/a | n/a | affected |
Weaknesses
- n/a
ADP Enrichment
CVE Program Container
Additional References
- http://www.osvdb.org/5369
- http://www.securityfocus.com/bid/10146
- http://news.postnuke.com/Article2580.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15869
- http://marc.info/?l=bugtraq&m=108256503718978&w=2
- http://lists.grok.org.uk/pipermail/full-disclosure/2004-April/020154.html
- http://www.osvdb.org/5368
- http://securitytracker.com/id?1009801
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15875
- http://secunia.com/advisories/11386
References
- http://www.osvdb.org/5369
- http://www.securityfocus.com/bid/10146
- http://news.postnuke.com/Article2580.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15869
- http://marc.info/?l=bugtraq&m=108256503718978&w=2
- http://lists.grok.org.uk/pipermail/full-disclosure/2004-April/020154.html
- http://www.osvdb.org/5368
- http://securitytracker.com/id?1009801
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15875
- http://secunia.com/advisories/11386
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.