VYPR
Unrated severityNVD Advisory· Published Dec 2, 2006· Updated Apr 23, 2026

CVE-2006-6233

CVE-2006-6233

Description

SQL injection vulnerability in the Downloads module for unknown versions of PostNuke allows remote attackers to execute arbitrary SQL commands via the lid parameter in a viewdownloaddetails operation. NOTE: this issue might have been in the viewdownloaddetails function in dl-downloaddetails.php, but PostNuke 0.764 does not appear to have this issue.

Affected products

10
  • Phpnuke/Postnuke10 versions
    cpe:2.3:a:postnuke_software_foundation:postnuke:0.760_rc2:*:*:*:*:*:*:*+ 9 more
    • cpe:2.3:a:postnuke_software_foundation:postnuke:0.760_rc2:*:*:*:*:*:*:*
    • cpe:2.3:a:postnuke_software_foundation:postnuke:0.760_rc3:*:*:*:*:*:*:*
    • cpe:2.3:a:postnuke_software_foundation:postnuke:0.760_rc4:*:*:*:*:*:*:*
    • cpe:2.3:a:postnuke_software_foundation:postnuke:0.761:*:*:*:*:*:*:*
    • cpe:2.3:a:postnuke_software_foundation:postnuke:0.761a:*:*:*:*:*:*:*
    • cpe:2.3:a:postnuke_software_foundation:postnuke:0.762:*:*:*:*:*:*:*
    • cpe:2.3:a:postnuke_software_foundation:postnuke:0.763:*:*:*:*:*:*:*
    • cpe:2.3:a:postnuke_software_foundation:postnuke:0.76_rc4:*:*:*:*:*:*:*
    • cpe:2.3:a:postnuke_software_foundation:postnuke:0.76_rc4a:*:*:*:*:*:*:*
    • cpe:2.3:a:postnuke_software_foundation:postnuke:0.76_rc4b:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.