Description
|
|
A vulnerability was identified in PostNuke, which may be exploited by malicious administrators to execute arbitrary SQL commands. This flaw is due to an input validation error in the "modules/Downloads/dl-viewdownload.php" script that does not properly filter a specially crafted "show" parameter, which may be exploited by administrators to execute arbitrary SQL commands.
|