PostNuke Remote SQL Injection Vulnerability
BID:5810
Info
PostNuke Remote SQL Injection Vulnerability
| Bugtraq ID: | 5810 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 26 2002 12:00AM |
| Updated: | Sep 26 2002 12:00AM |
| Credit: | Discovery credited to Pedro Inacio. |
| Vulnerable: |
PostNuke Development Team PostNuke 0.721 |
| Not Vulnerable: | |
Discussion
PostNuke Remote SQL Injection Vulnerability
A SQL injection vulnerability has been discovered in PostNuke.
Due to insufficient sanitization of variables used in SQL queries, it is possible to modify the logic of SQL queries.
This issue could result in a denial of service attack or the corruption of database information.
This issue was reported in PostNuke version 0.721. Other versions may also be affected.
A SQL injection vulnerability has been discovered in PostNuke.
Due to insufficient sanitization of variables used in SQL queries, it is possible to modify the logic of SQL queries.
This issue could result in a denial of service attack or the corruption of database information.
This issue was reported in PostNuke version 0.721. Other versions may also be affected.
Exploit / POC
PostNuke Remote SQL Injection Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
PostNuke Remote SQL Injection Vulnerability
Solution:
The PostNuke Development Team has a patch for this issue. Users of PostNuke 0.7.2.1 are advised to download and install this patch.
PostNuke Development Team PostNuke 0.721
Solution:
The PostNuke Development Team has a patch for this issue. Users of PostNuke 0.7.2.1 are advised to download and install this patch.
PostNuke Development Team PostNuke 0.721
References
PostNuke Remote SQL Injection Vulnerability
References:
References: