CVE-2003-1537
https://notcve.org/view.php?id=CVE-2003-1537
Directory traversal vulnerability in PostNuke 0.723 and earlier allows remote attackers to include arbitrary files named theme.php via the theme parameter to index.php. • http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0117.html • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •
CVE-2002-1996
https://notcve.org/view.php?id=CVE-2002-1996
Cross-site scripting (XSS) vulnerability in PostNuke 0.71 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) name parameter in modules.php and (2) catid parameter in index.php. • http://archives.neohapsis.com/archives/bugtraq/2002-03/0288.html http://archives.neohapsis.com/archives/bugtraq/2002-03/0299.html http://sourceforge.net/tracker/index.php?func=detail&aid=524777&group_id=27927&atid=392228 http://www.iss.net/security_center/static/8605.php http://www.securityfocus.com/bid/4350 •
CVE-2001-1521
https://notcve.org/view.php?id=CVE-2001-1521
Cross-site scripting (XSS) vulnerability in user.php in PostNuke 0.64 allows remote attackers to inject arbitrary web script or HTML via the uname parameter. • http://online.securityfocus.com/archive/1/245691 http://online.securityfocus.com/archive/82/243545 http://www.iss.net/security_center/static/7654.php http://www.securityfocus.com/bid/3609 •
CVE-2001-1460 – PostNuke 0.6 - User Login
https://notcve.org/view.php?id=CVE-2001-1460
SQL injection vulnerability in article.php in PostNuke 0.62 through 0.64 allows remote attackers to bypass authentication via the user parameter. • https://www.exploit-db.com/exploits/21119 http://archives.neohapsis.com/archives/bugtraq/2001-10/0088.html http://archives.neohapsis.com/archives/bugtraq/2001-10/0091.html http://www.kb.cert.org/vuls/id/921547 http://www.securityfocus.com/bid/3435 https://exchange.xforce.ibmcloud.com/vulnerabilities/7280 •