CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS
Percentile
65.7%
Two separate SQL injection vulnerabilities have been
identified in the PostNuke PHP content management
system. An attacker can use this vulnerability to
potentially insert executable PHP code into the content
management system (to view all files within the PHP scope,
for instance). Various other SQL injection vulnerabilities
exist, which give attackers the ability to run SQL queries
on any tables within the database.