PostNuke Admin.PHP SQL Injection Vulnerability
BID:20317
Info
PostNuke Admin.PHP SQL Injection Vulnerability
| Bugtraq ID: | 20317 |
| Class: | Input Validation Error |
| CVE: |
CVE-2006-5121 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 03 2006 12:00AM |
| Updated: | Dec 04 2006 04:24PM |
| Credit: | Omid is credited with the discovery of this vulnerability. |
| Vulnerable: |
PostNuke PostNuke CMS 0.762 |
| Not Vulnerable: |
PostNuke PostNuke CMS 0.763 |
Discussion
PostNuke Admin.PHP SQL Injection Vulnerability
PostNuke is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database implementation.
Version 0.762 is vulnerable; other versions may also be affected.
PostNuke is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database implementation.
Version 0.762 is vulnerable; other versions may also be affected.
Exploit / POC
PostNuke Admin.PHP SQL Injection Vulnerability
An attacker can exploit this issue via a web client.
An attacker can exploit this issue via a web client.
Solution / Fix
PostNuke Admin.PHP SQL Injection Vulnerability
Solution:
The vendor has addressed this issue in version 0.763 and later.
Solution:
The vendor has addressed this issue in version 0.763 and later.
References
PostNuke Admin.PHP SQL Injection Vulnerability
References:
References:
- PostNuke Homepage (PostNuke Development Team)