DotNetNuke System Message Information Disclosure Vulnerability
BID:39586
Info
DotNetNuke System Message Information Disclosure Vulnerability
| Bugtraq ID: | 39586 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 20 2010 12:00AM |
| Updated: | Apr 20 2010 12:00AM |
| Credit: | Stefan Cullman |
| Vulnerable: |
DotNetNuke DotNetNuke 5.3.1 DotNetNuke DotNetNuke 5.3 |
| Not Vulnerable: |
DotNetNuke DotNetNuke 5.4 |
Discussion
DotNetNuke System Message Information Disclosure Vulnerability
DotNetNuke is prone to an information-disclosure vulnerability.
Attackers can exploit this issue to gain access to sensitive information which may lead to other attacks.
DotNetNuke versions 5.3.0 up to and including 5.3.1 are vulnerable.
DotNetNuke is prone to an information-disclosure vulnerability.
Attackers can exploit this issue to gain access to sensitive information which may lead to other attacks.
DotNetNuke versions 5.3.0 up to and including 5.3.1 are vulnerable.
Exploit / POC
DotNetNuke System Message Information Disclosure Vulnerability
Attackers may exploit this issue through a browser.
Attackers may exploit this issue through a browser.
Solution / Fix
DotNetNuke System Message Information Disclosure Vulnerability
Solution:
Updates are available. Please see the references for details.
Solution:
Updates are available. Please see the references for details.
References
DotNetNuke System Message Information Disclosure Vulnerability
References:
References:
- DotNetNuke Homepage (DotNetNuke)
- System mails stored in cleartext in User messaging (DotNetNuke)