Show filters
14 Total Results
Displaying 11-14 of 14
Sort by:
Attacker Value
Unknown

CVE-2008-6542

Disclosure Date: March 30, 2009 (last updated October 04, 2023)
Unspecified vulnerability in the Skin Manager in DotNetNuke before 4.8.2 allows remote authenticated administrators to perform "server-side execution of application logic" by uploading a static file that is converted into a dynamic script via unknown vectors related to HTM or HTML files.
0
Attacker Value
Unknown

CVE-2008-6540

Disclosure Date: March 30, 2009 (last updated October 04, 2023)
DotNetNuke before 4.8.2, during installation or upgrade, does not warn the administrator when the default (1) ValidationKey and (2) DecryptionKey values cannot be modified in the web.config file, which allows remote attackers to bypass intended access restrictions by using the default keys.
0
Attacker Value
Unknown

CVE-2008-6541

Disclosure Date: March 30, 2009 (last updated October 04, 2023)
Unrestricted file upload vulnerability in the file manager module in DotNetNuke before 4.8.2 allows remote administrators to upload arbitrary files and gain privileges to the server via unspecified vectors.
0
Attacker Value
Unknown

CVE-2008-6399

Disclosure Date: March 05, 2009 (last updated October 04, 2023)
Unspecified vulnerability in DotNetNuke 4.5.2 through 4.9 allows remote attackers to "add additional roles to their user account" via unknown attack vectors.
0