DotNetNuke Unspecified HTML Injection Vulnerability
BID:66342
Info
DotNetNuke Unspecified HTML Injection Vulnerability
| Bugtraq ID: | 66342 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 19 2014 12:00AM |
| Updated: | Mar 19 2014 12:00AM |
| Credit: | Anonymous |
| Vulnerable: |
DotNetNuke DotNetNuke 7.1.1 DotNetNuke DotNetNuke 7.1 DotNetNuke DotNetNuke 7.0.6 DotNetNuke DotNetNuke 7.0 DotNetNuke DotNetNuke 7.0.5 DotNetNuke DotNetNuke 7.0.4 DotNetNuke DotNetNuke 7.0.3 DotNetNuke DotNetNuke 7.0.2 DotNetNuke DotNetNuke 7.0.1 |
| Not Vulnerable: |
DotNetNuke DotNetNuke 7.2.2 |
Discussion
DotNetNuke Unspecified HTML Injection Vulnerability
DotNetNuke is prone to an unspecified HTML-injection vulnerability because it fails to properly sanitize user-supplied input.
Attacker-supplied HTML and script code would run in the context of the affected website, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user.
Versions prior to DotNetNuke 7.2.2 are vulnerable.
DotNetNuke is prone to an unspecified HTML-injection vulnerability because it fails to properly sanitize user-supplied input.
Attacker-supplied HTML and script code would run in the context of the affected website, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user.
Versions prior to DotNetNuke 7.2.2 are vulnerable.
Exploit / POC
DotNetNuke Unspecified HTML Injection Vulnerability
An attacker can exploit this issue through a browser.
An attacker can exploit this issue through a browser.
Solution / Fix
DotNetNuke Unspecified HTML Injection Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.