Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Multiple cross-site scripting vulnerabilities in PostNuke 0.760-RC3 allow remote attackers to inject arbitrary web script or HTML via the (1) module parameter to admin.php or (2) op parameter to user.php. NOTE: the vendor reports that certain issues could not be reproduced for 760 RC3, or for .750. However, the op/user.php issue exists when the pnAntiCracker setting is disabled.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
PostNuke多个模块SQL注入/跨站脚本及路径泄露漏洞
Vulnerability Description
PostNuke是一个广为流行的网站创建和管理工具,可以使用很多数据库软件作为后端。PostNuke的News模块中存在多个安全漏洞,远程攻击者可能利用这些漏洞进行SQL注入、跨站脚本执行、获取敏感信息等攻击。
CVSS Information
N/A
Vulnerability Type
N/A