CVE-2007-2492
SQL injection vulnerability in index.php in the v4bJournal module for PostNuke allows remote authenticated users to execute arbitrary SQL commands via the id parameter in a journal_comment action.
- Affected products
- Postnuke
- Postnuke Software Foundation Postnuke v4bjournal Module
- = 0.99
- Fix
- Available
- CVSS 2.0
- 7.5 HIGH
- EPSS
- 1.2% (66th percentile)
- NVD status
- Modified
- Published
- 2007-05-04
CVE-2007-2492 at NVD
1 known exploit for CVE-2007-2492
Proof-of-concept code and exploit modules indexed by Sploitus