CVE-2005-2690 Information

Description

SQL injection vulnerability in the Downloads module in PostNuke 0.760-RC4b allows PostNuke administrators to execute arbitrary SQL commands via the show parameter to dl-viewdownload.php.

Reference

http://www.securityfocus.com/archive/1/408818 http://www.securityfocus.com/bid/14636

Share on: