← Vulnerability feed

Vulnerability record · CVE-2006-5121 · published 3 October 2006

CVE-2006-5121: Postnuke software foundation postnuke vulnerability

PPostnuke Software Foundation · Postnuke

SQL injection vulnerability in modules/Downloads/admin.php in the Admin section of PostNuke 0.762 allows remote attackers to execute arbitrary SQL commands via the hits parameter.

7.5 CVSS 2.0 High EPSS 1.4% · top 29.5%
7.5CVSS 2.0 base score
1.4%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
14References
16 Jun 2026Last modified by NVD

Description

SQL injection vulnerability in modules/Downloads/admin.php in the Admin section of PostNuke 0.762 allows remote attackers to execute arbitrary SQL commands via the hits parameter.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2006-5121 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2007-0386Postnuke software foundation postnuke vulnerabilityUnspecified vulnerability in the rating section in PostNuke 0.764 has unknown impact and attack vectors, related to "an interesting bug."EPSS 1.5%7.8CVE-2007-0385Postnuke software foundation postnuke vulnerabilityThe faq section in PostNuke 0.764 allows remote attackers to obtain sensitive information (the full path) via "unvalidated output" in FAQ/index.php, …EPSS 1.5%7.8CVE-2006-6267Postnuke software foundation postnuke vulnerabilityPostNuke 0.7.5.0, and certain minor versions, allows remote attackers to obtain sensitive information via a non-numeric value of the stop parameter, …EPSS 1.4%7.5CVE-2006-6233Postnuke software foundation postnuke vulnerabilitySQL injection vulnerability in the Downloads module for unknown versions of PostNuke allows remote attackers to execute arbitrary SQL commands via th…EPSS 1.1%7.5CVE-2006-5733Postnuke software foundation postnuke vulnerabilityDirectory traversal vulnerability in error.php in PostNuke 0.763 and earlier allows remote attackers to include and execute arbitrary local files via…EPSS 3.0%7.5CVE-2006-0146John lim adodb sql injection vulnerabilityThe server.php test script in ADOdb for PHP before 4.70, as used in multiple products including (1) Mantis, (2) PostNuke, (3) Moodle, (4) Cacti, (5) …EPSS 13%7.5CVE-2006-0147John lim adodb vulnerabilityDynamic code evaluation vulnerability in tests/tmssql.php test script in ADOdb for PHP before 4.70, as used in multiple products including (1) Mantis…EPSS 13%7.5CVE-2005-2690Postnuke software foundation postnuke vulnerabilitySQL injection vulnerability in the Downloads module in PostNuke 0.760-RC4b allows PostNuke administrators to execute arbitrary SQL commands via the s…EPSS 0.98%

Source: NIST National Vulnerability Database (record CVE-2006-5121), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.