Back
CVE-2004-2751
SQL injection vulnerability in the members_list module in PostNuke 0.726, and possibly earlier, allows remote attackers to execute arbitrary SQL commands via the sortby parameter.
Published: Dec 31, 2004
Modified: Jun 16, 2026
CWE-89
CVSS Metrics
Affected Products (3)
| Vendor | Product | Version |
|---|---|---|
| postnuke_software_foundation | postnuke | 0.722 |
| postnuke_software_foundation | postnuke | 0.723 |
| postnuke_software_foundation | postnuke | 0.726 |
GitHub Security Advisory GHSA-r3xr-78mf-93cp
SQL injection vulnerability in the members_list module in PostNuke 0.726, and possibly earlier,...
References (16)
- http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0117.html Exploit
- http://community.postnuke.com/Article2535.htm Patch
- http://lists.postnuke.com/pipermail/postnuke-security/2004q1/000001.html
- http://securitytracker.com/id?1008629
- http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2004-01/0015.html Patch
- http://www.gulftech.org/01032004.php
- http://www.osvdb.org/3334
- https://exchange.xforce.ibmcloud.com/vulnerabilities/11500
- http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0117.html Exploit
- http://community.postnuke.com/Article2535.htm Patch
- http://lists.postnuke.com/pipermail/postnuke-security/2004q1/000001.html
- http://securitytracker.com/id?1008629
- http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2004-01/0015.html Patch
- http://www.gulftech.org/01032004.php
- http://www.osvdb.org/3334
Risk Scores
CVSS Score
6.8 / 10
EPSS Score
1.35%
Top 31% most likely to be exploited
Threat Score
27.6 / 100
Data Sources
NVD
EPSS
GitHub