Unrated severityNVD Advisory· Published May 2, 2005· Updated Apr 16, 2026
CVE-2005-1049
CVE-2005-1049
Description
Multiple cross-site scripting vulnerabilities in PostNuke 0.760-RC3 allow remote attackers to inject arbitrary web script or HTML via the (1) module parameter to admin.php or (2) op parameter to user.php. NOTE: the vendor reports that certain issues could not be reproduced for 760 RC3, or for .750. However, the op/user.php issue exists when the pnAntiCracker setting is disabled.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
10- cvs.postnuke.com/viewcvs.cgi/Historic_PostNuke_Library/postnuke-devel/html/user.php.diffnvdPatch
- news.postnuke.com/modules.phpnvdPatchVendor Advisory
- secunia.com/advisories/14868/nvdExploitPatchVendor Advisory
- www.securityfocus.com/bid/13075nvdExploit
- www.securityfocus.com/bid/13076nvdExploitPatch
- digitalparadox.org/advisories/postnuke.txtnvd
- marc.infonvd
- securitytracker.com/idnvd
- www.osvdb.org/15370nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/20018nvd
News mentions
0No linked articles in our index yet.