Multiple SQL injection vulnerabilities in Xanthia.php in the Xanthia module in PostNuke 0.750 allow remote attackers to execute arbitrary SQL commands via the (1) name or (2) module parameter.
http://news.postnuke.com/modules.php?op=modload&name=News&file=article&sid=2691