Show filters
14 Total Results
Displaying 11-14 of 14
Sort by:
Attacker Value
Unknown
CVE-2008-6542
Disclosure Date: March 30, 2009 (last updated October 04, 2023)
Unspecified vulnerability in the Skin Manager in DotNetNuke before 4.8.2 allows remote authenticated administrators to perform "server-side execution of application logic" by uploading a static file that is converted into a dynamic script via unknown vectors related to HTM or HTML files.
0
Attacker Value
Unknown
CVE-2008-6540
Disclosure Date: March 30, 2009 (last updated October 04, 2023)
DotNetNuke before 4.8.2, during installation or upgrade, does not warn the administrator when the default (1) ValidationKey and (2) DecryptionKey values cannot be modified in the web.config file, which allows remote attackers to bypass intended access restrictions by using the default keys.
0
Attacker Value
Unknown
CVE-2008-6541
Disclosure Date: March 30, 2009 (last updated October 04, 2023)
Unrestricted file upload vulnerability in the file manager module in DotNetNuke before 4.8.2 allows remote administrators to upload arbitrary files and gain privileges to the server via unspecified vectors.
0
Attacker Value
Unknown
CVE-2008-6399
Disclosure Date: March 05, 2009 (last updated October 04, 2023)
Unspecified vulnerability in DotNetNuke 4.5.2 through 4.9 allows remote attackers to "add additional roles to their user account" via unknown attack vectors.
0