HIGH · 7.5

CVE-2005-1048

SQL injection vulnerability in modules.php in PostNuke 0.760 RC3 allows remote attackers to execute arbitrary SQL statements via the sid parameter. NOTE: the vendor reports that they could not reprod...

Vulnerability Description

SQL injection vulnerability in modules.php in PostNuke 0.760 RC3 allows remote attackers to execute arbitrary SQL statements via the sid parameter. NOTE: the vendor reports that they could not reproduce the issues for 760 RC3, or for .750.

CVSS Score

7.5

HIGH

AV:N/AC:L/Au:N/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
Postnuke Software FoundationPostnuke0.760_rc3

References

FAQ

What is CVE-2005-1048?

CVE-2005-1048 is a vulnerability with a CVSS score of 7.5 (HIGH). SQL injection vulnerability in modules.php in PostNuke 0.760 RC3 allows remote attackers to execute arbitrary SQL statements via the sid parameter. NOTE: the vendor reports that they could not reprod...

How severe is CVE-2005-1048?

CVE-2005-1048 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2005-1048?

Check the references section above for vendor advisories and patch information. Affected products include: Postnuke Software Foundation Postnuke.