Show filters
13 Total Results
Displaying 11-13 of 13
Sort by:
Attacker Value
Unknown

CVE-2008-6540

Disclosure Date: March 30, 2009 (last updated October 04, 2023)
DotNetNuke before 4.8.2, during installation or upgrade, does not warn the administrator when the default (1) ValidationKey and (2) DecryptionKey values cannot be modified in the web.config file, which allows remote attackers to bypass intended access restrictions by using the default keys.
0
Attacker Value
Unknown

CVE-2008-6541

Disclosure Date: March 30, 2009 (last updated October 04, 2023)
Unrestricted file upload vulnerability in the file manager module in DotNetNuke before 4.8.2 allows remote administrators to upload arbitrary files and gain privileges to the server via unspecified vectors.
0
Attacker Value
Unknown

CVE-2006-4973

Disclosure Date: September 25, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Default.aspx in Perpetual Motion Interactive Systems DotNetNuke before 3.3.5, and 4.x before 4.3.5, allows remote attackers to inject arbitrary HTML via the error parameter.
0