From 14e9f262540b26285ade47dca002e58b0f20f76a Mon Sep 17 00:00:00 2001 From: simon Date: Sun, 7 Aug 2005 22:19:56 +0000 Subject: Document postnuke -- multiple vulnerabilities. Approved by: portmgr (blanket, VuXML) --- security/vuxml/vuln.xml | 47 +++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 47 insertions(+) (limited to 'security/vuxml') diff --git a/security/vuxml/vuln.xml b/security/vuxml/vuln.xml index 01bc2da09fb6..b6228cc4fcc9 100644 --- a/security/vuxml/vuln.xml +++ b/security/vuxml/vuln.xml @@ -32,6 +32,53 @@ EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. --> + + postnuke -- multiple vulnerabilities + + + postnuke + 0.760 + + + + +

Postnuke Security Announcementss reports of the following + vulnerabilities:

+
+
    +
  • missing input validation within /modules/Messages/readpmsg.php
  • +
  • possible path disclosure within /user.php
  • +
  • possible path disclosure within /modules/News/article.php
  • +
  • possible remote code injection within /includes/pnMod.php
  • +
  • possible cross-site-scripting in /index.php
  • +
+
+
+
    +
  • remote code injection via xml rpc library
  • +
+
+ +
+ + CAN-2005-1621 + CAN-2005-1695 + CAN-2005-1696 + CAN-2005-1698 + CAN-2005-1777 + CAN-2005-1778 + CAN-2005-1921 + http://marc.theaimsgroup.com/?l=bugtraq&m=111721364707520 + http://secunia.com/advisories/15450/ + http://news.postnuke.com/Article2691.html + http://news.postnuke.com/Article2699.html + + + 2005-05-27 + 2005-08-08 + +
+ mambo -- multiple vulnerabilities -- cgit