VULNERABILITY INTELLIGENCE

CVE-2008-2013

CVSS score6.8 MEDIUM
EPSS probability1.04%
CISA KEVNot currently listed
Published2008-04-30
Last modified2026-06-16

Description

SQL injection vulnerability in index.php in the pnFlashGames 1.5 through 2.5 module for PostNuke, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter in a display action.