Shodan
Maps
Images
Monitor
Developer
More...
Dashboard
View Api Docs
Vulnerabilities
By Date
Known Exploited
Advanced Search
Vulnerable Software
Vendors
Products
Vulnerability Details CVE-2004-1949
SQL injection vulnerability in PostNuke 7.2.6 and earlier allows remote attackers to execute arbitrary SQL via (1) the sif parameter to index.php in the Comments module or (2) timezoneoffset parameter to changeinfo.php in the Your_Account module.
Exploit prediction scoring system (EPSS) score
EPSS Score
0.019
EPSS Ranking
82.3%
CVSS Severity
CVSS v2 Score
7.5
References
http://lists.grok.org.uk/pipermail/full-disclosure/2004-April/020154.html
http://marc.info/?l=bugtraq&m=108256503718978&w=2
http://news.postnuke.com/Article2580.html
http://secunia.com/advisories/11386
http://securitytracker.com/id?1009801
http://www.osvdb.org/5368
http://www.osvdb.org/5369
http://www.securityfocus.com/bid/10146
https://exchange.xforce.ibmcloud.com/vulnerabilities/15869
https://exchange.xforce.ibmcloud.com/vulnerabilities/15875
http://lists.grok.org.uk/pipermail/full-disclosure/2004-April/020154.html
http://marc.info/?l=bugtraq&m=108256503718978&w=2
http://news.postnuke.com/Article2580.html
http://secunia.com/advisories/11386
http://securitytracker.com/id?1009801
http://www.osvdb.org/5368
http://www.osvdb.org/5369
http://www.securityfocus.com/bid/10146
https://exchange.xforce.ibmcloud.com/vulnerabilities/15869
https://exchange.xforce.ibmcloud.com/vulnerabilities/15875
Products affected by CVE-2004-1949
Postnuke Software Foundation
»
Postnuke
»
Version:
0.726
cpe:2.3:a:postnuke_software_foundation:postnuke:0.726
Products
Monitor
Search Engine
Developer API
Maps
Bulk Data
Images
Snippets
Pricing
Membership
API Subscriptions
Enterprise
Contact Us
support@shodan.io
Shodan ® - All rights reserved