PT-2008-3147 · Postnuke · Postnuke

The:Paradox

·

Published

2008-03-31

·

Updated

2017-09-29

·

CVE-2008-1591

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions PostNuke versions 0.764 and earlier
Description The issue allows remote attackers to conduct SQL injection attacks and execute arbitrary SQL commands via input associated with server variables, such as the CLIENT IP HTTP header (HTTP CLIENT IP variable), due to the pnVarPrepForStore function skipping input sanitization when magic quotes runtime is enabled.
Recommendations For PostNuke versions 0.764 and earlier, consider disabling the pnVarPrepForStore function or restricting input associated with server variables until a patch is available. Additionally, disabling magic quotes runtime may help mitigate the risk of SQL injection attacks.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-1591

Affected Products

Postnuke