Back
CVE-2001-1460
SQL injection vulnerability in article.php in PostNuke 0.62 through 0.64 allows remote attackers to bypass authentication via the user parameter.
Published: Oct 13, 2001
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (3)
| Vendor | Product | Version |
|---|---|---|
| postnuke_software_foundation | postnuke | 0.62 |
| postnuke_software_foundation | postnuke | 0.63 |
| postnuke_software_foundation | postnuke | 0.64 |
GitHub Security Advisory GHSA-hp48-5ppw-8mm6
SQL injection vulnerability in article.php in PostNuke 0.62 through 0.64 allows remote attackers...
References (10)
- http://archives.neohapsis.com/archives/bugtraq/2001-10/0088.html Exploit, Patch
- http://archives.neohapsis.com/archives/bugtraq/2001-10/0091.html
- http://www.kb.cert.org/vuls/id/921547 Third Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/3435 Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/7280
- http://archives.neohapsis.com/archives/bugtraq/2001-10/0088.html Exploit, Patch
- http://archives.neohapsis.com/archives/bugtraq/2001-10/0091.html
- http://www.kb.cert.org/vuls/id/921547 Third Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/3435 Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/7280
Risk Scores
CVSS Score
7.5 / 10
EPSS Score
3.28%
Top 13% most likely to be exploited
Threat Score
31 / 100
Data Sources
NVD
EPSS
GitHub