AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2004-1949

HIGH · CVSS 7.5 EPSS 1.96%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2004-12-31 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2004-1949
Severity
HIGH
CVSS
7.5
EPSS
1.96%

Original NVD Description

SQL injection vulnerability in PostNuke 7.2.6 and earlier allows remote attackers to execute arbitrary SQL via (1) the sif parameter to index.php in the Comments module or (2) timezoneoffset parameter to changeinfo.php in the Your_Account module.