DotNetNuke ResponsiveSidebar 'ResponsiveSidebarDownload.aspx' Arbitrary File Download Vulnerabilitiy
BID:67960
Info
DotNetNuke ResponsiveSidebar 'ResponsiveSidebarDownload.aspx' Arbitrary File Download Vulnerabilitiy
| Bugtraq ID: | 67960 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 10 2014 12:00AM |
| Updated: | Jun 10 2014 12:00AM |
| Credit: | alieye |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
DotNetNuke ResponsiveSidebar 'ResponsiveSidebarDownload.aspx' Arbitrary File Download Vulnerabilitiy
DotNetNuke ResponsiveSidebar is prone to an arbitrary-file-download vulnerability.
An attacker can exploit this issue to download arbitrary files from the Web server and obtain potentially sensitive information.
DotNetNuke ResponsiveSidebar is prone to an arbitrary-file-download vulnerability.
An attacker can exploit this issue to download arbitrary files from the Web server and obtain potentially sensitive information.
Exploit / POC
DotNetNuke ResponsiveSidebar 'ResponsiveSidebarDownload.aspx' Arbitrary File Download Vulnerabilitiy
Attackers can use a browser to exploit this issue.
Attackers can use a browser to exploit this issue.
Solution / Fix
DotNetNuke ResponsiveSidebar 'ResponsiveSidebarDownload.aspx' Arbitrary File Download Vulnerabilitiy
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
DotNetNuke ResponsiveSidebar 'ResponsiveSidebarDownload.aspx' Arbitrary File Download Vulnerabilitiy
References:
References:
- DotNetNuke homepage (Mediaant)