FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2006-5121

This CVE name corresponds to:

Entered Topic
2006-10-03 postnuke -- admin section SQL injection

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2006-5121
Phase Assigned(20061002)

Description

SQL injection vulnerability in modules/Downloads/admin.php in the Admin section of PostNuke 0.762 allows remote attackers to execute arbitrary SQL commands via the hits parameter.

References

Source Reference
BUGTRAQ 20060929 Sql injection in PostNuke [Admin section]
CONFIRM http://community.postnuke.com/index.php?name=News&file=article&sid=2783
BID 20317
VUPEN ADV-2006-3886
SECUNIA 22197
SREASON 1669
XF postnuke-admin-sql-injection(29271)