SQL injection vulnerability in modules.php in PostNuke 0.760 RC3 allows remote attackers to execute arbitrary SQL statements via the sid parameter. NOTE: the vendor reports that they could not reproduce the issues for 760 RC3, or for .750.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Postnuke | Postnuke_software_foundation | 0.760_rc3 (including) | 0.760_rc3 (including) |