Multiple SQL injection vulnerabilities in Xanthia.php in the Xanthia module in PostNuke 0.750 allow remote attackers to execute arbitrary SQL commands via the (1) name or (2) module parameter.
Link | Tags |
---|---|
http://marc.info/?l=bugtraq&m=111670823128472&w=2 | mailing list |
http://news.postnuke.com/modules.php?op=modload&name=News&file=article&sid=2691 | patch vendor advisory |