PT-2008-3533 · Postnuke · Postnuke Pnflashgames Module

Kacper

·

Published

2008-04-30

·

Updated

2017-09-29

·

CVE-2008-2013

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions PostNuke pnFlashGames module versions 1.5 through 2.5
Description The issue allows remote attackers to execute arbitrary SQL commands. This is possible when the magic quotes gpc setting is disabled. The id parameter in a display action is vulnerable to SQL injection.
Recommendations For PostNuke pnFlashGames module versions 1.5 through 2.5, consider disabling the display action until a patch is available, and ensure magic quotes gpc is enabled to mitigate the risk of SQL injection via the id parameter.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-2013

Affected Products

Postnuke Pnflashgames Module