DotNetNuke ASPSlideshow 'ASPSlideShowDownload.aspx' Arbitrary File Download Vulnerabilitiy
BID:67950
Info
DotNetNuke ASPSlideshow 'ASPSlideShowDownload.aspx' Arbitrary File Download Vulnerabilitiy
| Bugtraq ID: | 67950 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 09 2014 12:00AM |
| Updated: | Jun 09 2014 12:00AM |
| Credit: | alieye |
| Vulnerable: |
DotNetNuke ASPSlideshow 0 |
| Not Vulnerable: | |
Discussion
DotNetNuke ASPSlideshow 'ASPSlideShowDownload.aspx' Arbitrary File Download Vulnerabilitiy
DotNetNuke ASPSlideshow is prone to an arbitrary-file-download vulnerability.
An attacker can exploit this issue to download arbitrary files from the Web server and obtain potentially sensitive information.
DotNetNuke ASPSlideshow is prone to an arbitrary-file-download vulnerability.
An attacker can exploit this issue to download arbitrary files from the Web server and obtain potentially sensitive information.
References
DotNetNuke ASPSlideshow 'ASPSlideShowDownload.aspx' Arbitrary File Download Vulnerabilitiy
References:
References:
- DotNetNuke homepage (Mediaant)