Multiple SQL injection vulnerabilities in (1) index.php, (2) modules.php, or (3) admin.php in PostNuke 0.760-RC2 allow remote attackers to execute arbitrary SQL code via the catid parameter.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Postnuke | Postnuke_software_foundation | 0.760_rc2 (including) | 0.760_rc2 (including) |