DotNetNuke Multiple Security Bypass and HTML Injection Vulnerabilities
BID:56577
Info
DotNetNuke Multiple Security Bypass and HTML Injection Vulnerabilities
| Bugtraq ID: | 56577 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 11 2012 12:00AM |
| Updated: | Nov 11 2012 12:00AM |
| Credit: | Sunil Yadav via Secunia, Chris Hammond and Rutger Buijzen (DotControl) |
| Vulnerable: |
DotNetNuke DotNetNuke 6.2.4 DotNetNuke DotNetNuke 6.2.1 DotNetNuke DotNetNuke 6.2.0 |
| Not Vulnerable: |
DotNetNuke DotNetNuke 6.2.7 |
Discussion
DotNetNuke Multiple Security Bypass and HTML Injection Vulnerabilities
DotNetNuke is prone to the following security vulnerabilities:
1. Multiple security-bypass
2. Multiple HTML-injection
Successfully exploiting these issues may allow attackers to bypass certain security restrictions and execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
DotNetNuke versions prior to 6.2.5 are vulnerable.
DotNetNuke is prone to the following security vulnerabilities:
1. Multiple security-bypass
2. Multiple HTML-injection
Successfully exploiting these issues may allow attackers to bypass certain security restrictions and execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
DotNetNuke versions prior to 6.2.5 are vulnerable.
Exploit / POC
DotNetNuke Multiple Security Bypass and HTML Injection Vulnerabilities
Attackers can use a browser to exploit these issues.
Attackers can use a browser to exploit these issues.