eNvolution, the fork of PostNuke, is susceptible to cross site scripting and SQL injection attacks.
865c68bd2e1d4c7b91f6db4fb634ae6b79e22185ec0f60cfad95bdde189f228f
[Description]: eNvolution is a fork of PostNuke. The entire core of the product is being replaced and improved, making it far more secure and stable, and able to work in high-volume environments with ease.
[vendor]: https://www.envolution.com
[Vulnerability]: SQL injection AND XSS
[sploit]
https://[host]/[envo]/modules.php?op=modload&name=News&file=index&catid=&topic=18&startrow=[sql] or [xss]
https://[host]/[envo]/modules.php?op=modload&name=News&file=index&catid=[sql] or [xss]
x1ng
X1ngBox |4t| gmail C0m