VYPR

NS-Languages

by Postnuke

CVEs (2)

  • CVE-2006-0801Feb 20, 2006
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in the NS-Languages module for PostNuke 0.761 and earlier, when magic_quotes_gpc is off, allows remote attackers to execute arbitrary SQL commands via the language parameter to admin.php.

  • CVE-2006-0802Feb 20, 2006
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in the NS-Languages module for PostNuke 0.761 and earlier, when magic_quotes_gpc is enabled, allows remote attackers to inject arbitrary web script or HTML via the language parameter in a missing or translation operation.