Back

CVE-2004-2751

SQL injection vulnerability in the members_list module in PostNuke 0.726, and possibly earlier, allows remote attackers to execute arbitrary SQL commands via the sortby parameter.

Published: Dec 31, 2004 Modified: Jun 16, 2026
CWE-89

CVSS Metrics

Affected Products (3)

Vendor Product Version
postnuke_software_foundation postnuke 0.722
postnuke_software_foundation postnuke 0.723
postnuke_software_foundation postnuke 0.726

GitHub Security Advisory GHSA-r3xr-78mf-93cp

SQL injection vulnerability in the members_list module in PostNuke 0.726, and possibly earlier,...

Risk Scores

CVSS Score 6.8 / 10
EPSS Score 1.35%

Top 31% most likely to be exploited

Threat Score 27.6 / 100

Data Sources

NVD EPSS GitHub