Multiple SQL injection vulnerabilities in (1) index.php, (2) modules.php, or (3) admin.php in PostNuke 0.760-RC2 allow remote attackers to execute arbitrary SQL code via the catid parameter.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Postnuke | Postnuke_software_foundation | 0.760_rc2 (including) | 0.760_rc2 (including) |