CVE List

Id CVE No. Status Description Phase Votes Comments Actions
12900  CVE-2005-1694  Candidate  Multiple SQL injection vulnerabilities in Xanthia.php in the Xanthia module in PostNuke 0.750 allow remote attackers to execute arbitrary SQL commands via the (1) name or (2) module parameter.  Assigned (20050524)  None (candidate not yet proposed)    View
12901  CVE-2005-1695  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in the RSS module in PostNuke 0.750 and 0.760RC2 and RC3 allow remote attackers to inject arbitrary web script or HTML via the (1) rss_url parameter to magpie_slashbox.php, or the url parameter to (2) magpie_simple.php or (3) magpie_debug.php.  Assigned (20050524)  None (candidate not yet proposed)    View
12902  CVE-2005-1696  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in PostNuke 0.750 and 0.760RC3 allow remote attackers to inject arbitrary web script or HTML via the (1) skin or (2) paletteid parameter to demo.php in the Xanthia module, or (3) the serverName parameter to config.php in the Multisites (aka NS-Multisites) module.  Assigned (20050524)  None (candidate not yet proposed)    View
12903  CVE-2005-1697  Candidate  The RSS module in PostNuke 0.750 and 0.760RC2 and RC3 allows remote attackers to obtain sensitive information via a direct request to simple_smarty.php, which reveals the path in an error message.  Assigned (20050524)  None (candidate not yet proposed)    View
12904  CVE-2005-1698  Candidate  PostNuke 0.750 and 0.760RC3 allows remote attackers to obtain sensitive information via a direct request to (1) theme.php or (2) Xanthia.php in the Xanthia module, (3) user.php, (4) thelang.php, (5) text.php, (6) html.php, (7) menu.php, (8) finclude.php, or (9) button.php in the pnblocks directory in the Blocks module, (10) config.php in the NS-Multisites (aka Multisites) module, or (11) xmlrpc.php, which reveals the path in an error message.  Assigned (20050524)  None (candidate not yet proposed)    View

Page 1599 of 20943, showing 5 records out of 104715 total, starting on record 7991, ending on 7995

Actions