DotNetNuke Multiple Security Bypass and Information Disclosure Vulnerabilities
BID:31145
Info
DotNetNuke Multiple Security Bypass and Information Disclosure Vulnerabilities
| Bugtraq ID: | 31145 |
| Class: | Access Validation Error |
| CVE: |
CVE-2008-7101 CVE-2008-7102 CVE-2008-7100 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 09 2008 12:00AM |
| Updated: | Jul 05 2016 10:01PM |
| Credit: | Brandon Haynes |
| Vulnerable: |
DotNetNuke DotNetNuke 4.8.4 DotNetNuke DotNetNuke 4.8.3 DotNetNuke DotNetNuke 4.8.2 DotNetNuke DotNetNuke 4.8.1 DotNetNuke DotNetNuke 4.3.5 DotNetNuke DotNetNuke 3.3.5 DotNetNuke DotNetNuke 3.1 .0 DotNetNuke DotNetNuke 3.0.8 DotNetNuke DotNetNuke 3.0.7 DotNetNuke DotNetNuke 2.1.2 DotNetNuke DotNetNuke 2.1.1 DotNetNuke DotNetNuke 4.0 |
| Not Vulnerable: |
DotNetNuke DotNetNuke 4.9 |
Discussion
DotNetNuke Multiple Security Bypass and Information Disclosure Vulnerabilities
DotNetNuke is prone to multiple vulnerabilities.
Attackers can exploit these issues to bypass certain security restrictions or obtain sensitive information.
The issues affect DotNetNuke 2.0 up to and including 4.8.4.
DotNetNuke is prone to multiple vulnerabilities.
Attackers can exploit these issues to bypass certain security restrictions or obtain sensitive information.
The issues affect DotNetNuke 2.0 up to and including 4.8.4.
Exploit / POC
DotNetNuke Multiple Security Bypass and Information Disclosure Vulnerabilities
Attackers can use a browser to exploit these issues.
Attackers can use a browser to exploit these issues.
Solution / Fix
DotNetNuke Multiple Security Bypass and Information Disclosure Vulnerabilities
Solution:
The vendor has released an update. Please see the references for more information.
Solution:
The vendor has released an update. Please see the references for more information.
References
DotNetNuke Multiple Security Bypass and Information Disclosure Vulnerabilities
References:
References:
- DotNetNuke Homepage (DotNetNuke)
- Authentication blindspot in User functions (DotNetNuke)
- Failure to validation when loading skins (DotNetNuke)
- Install wizard information leakage (DotNetNuke)