Show filters
45 Total Results
Displaying 11-20 of 45
Sort by:
Attacker Value
Unknown
CVE-2018-18325
Disclosure Date: July 03, 2019 (last updated November 27, 2024)
DNN (aka DotNetNuke) 9.2 through 9.2.2 uses a weak encryption algorithm to protect input parameters. NOTE: this issue exists because of an incomplete fix for CVE-2018-15811.
0
Attacker Value
Unknown
CVE-2018-18326
Disclosure Date: July 03, 2019 (last updated November 27, 2024)
DNN (aka DotNetNuke) 9.2 through 9.2.2 incorrectly converts encryption key source values, resulting in lower than expected entropy. NOTE: this issue exists because of an incomplete fix for CVE-2018-15812.
0
Attacker Value
Unknown
CVE-2018-15811
Disclosure Date: July 03, 2019 (last updated November 27, 2024)
DNN (aka DotNetNuke) 9.2 through 9.2.1 uses a weak encryption algorithm to protect input parameters.
0
Attacker Value
Unknown
CVE-2018-14486
Disclosure Date: March 21, 2019 (last updated November 27, 2024)
DNN (formerly DotNetNuke) 9.1.1 allows cross-site scripting (XSS) via XML.
0
Attacker Value
Unknown
CVE-2017-0929
Disclosure Date: July 03, 2018 (last updated November 27, 2024)
DNN (aka DotNetNuke) before 9.2.0 suffers from a Server-Side Request Forgery (SSRF) vulnerability in the DnnImageHandler class. Attackers may be able to access information about internal network resources.
0
Attacker Value
Unknown
CVE-2017-9822
Disclosure Date: July 20, 2017 (last updated July 25, 2024)
DNN (aka DotNetNuke) before 9.1.1 has Remote Code Execution via a cookie, aka "2017-08 (Critical) Possible remote code execution on DNN sites."
0
Attacker Value
Unknown
CVE-2015-2794
Disclosure Date: February 06, 2017 (last updated November 26, 2024)
The installation wizard in DotNetNuke (DNN) before 7.4.1 allows remote attackers to reinstall the application and gain SuperUser access via a direct request to Install/InstallWizard.aspx.
0
Attacker Value
Unknown
CVE-2016-7119
Disclosure Date: August 31, 2016 (last updated November 25, 2024)
Cross-site scripting (XSS) vulnerability in the user-profile biography section in DotNetNuke (DNN) before 8.0.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted onclick attribute in an IMG element.
0
Attacker Value
Unknown
CVE-2015-1566
Disclosure Date: February 09, 2015 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in DotNetNuke (DNN) before 7.4.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown
CVE-2013-7335
Disclosure Date: March 12, 2014 (last updated October 05, 2023)
Open redirect vulnerability in DotNetNuke (DNN) before 6.2.9 and 7.x before 7.1.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
0