Show filters
55 Total Results
Displaying 41-50 of 55
Sort by:
Attacker Value
Unknown
CVE-2019-12562
Disclosure Date: September 26, 2019 (last updated November 27, 2024)
Stored Cross-Site Scripting in DotNetNuke (DNN) Version before 9.4.0 allows remote attackers to store and embed the malicious script into the admin notification page. The exploit could be used to perfom any action with admin privileges such as managing content, adding users, uploading backdoors to the server, etc. Successful exploitation occurs when an admin user visits a notification page with stored cross-site scripting.
0
Attacker Value
Unknown
CVE-2018-18570
Disclosure Date: July 29, 2019 (last updated November 27, 2024)
Planon before Live Build 41 has XSS.
0
Attacker Value
Unknown
CVE-2018-15812
Disclosure Date: July 03, 2019 (last updated November 27, 2024)
DNN (aka DotNetNuke) 9.2 through 9.2.1 incorrectly converts encryption key source values, resulting in lower than expected entropy.
0
Attacker Value
Unknown
CVE-2018-18325
Disclosure Date: July 03, 2019 (last updated November 27, 2024)
DNN (aka DotNetNuke) 9.2 through 9.2.2 uses a weak encryption algorithm to protect input parameters. NOTE: this issue exists because of an incomplete fix for CVE-2018-15811.
0
Attacker Value
Unknown
CVE-2018-15811
Disclosure Date: July 03, 2019 (last updated November 27, 2024)
DNN (aka DotNetNuke) 9.2 through 9.2.1 uses a weak encryption algorithm to protect input parameters.
0
Attacker Value
Unknown
CVE-2018-18326
Disclosure Date: July 03, 2019 (last updated November 27, 2024)
DNN (aka DotNetNuke) 9.2 through 9.2.2 incorrectly converts encryption key source values, resulting in lower than expected entropy. NOTE: this issue exists because of an incomplete fix for CVE-2018-15812.
0
Attacker Value
Unknown
CVE-2018-14486
Disclosure Date: March 21, 2019 (last updated November 27, 2024)
DNN (formerly DotNetNuke) 9.1.1 allows cross-site scripting (XSS) via XML.
0
Attacker Value
Unknown
CVE-2018-0646
Disclosure Date: September 04, 2018 (last updated November 27, 2024)
Directory traversal vulnerability in Explzh v.7.58 and earlier allows an attacker to read arbitrary files via unspecified vectors.
0
Attacker Value
Unknown
CVE-2017-0929
Disclosure Date: July 03, 2018 (last updated November 27, 2024)
DNN (aka DotNetNuke) before 9.2.0 suffers from a Server-Side Request Forgery (SSRF) vulnerability in the DnnImageHandler class. Attackers may be able to access information about internal network resources.
0
Attacker Value
Unknown
CVE-2017-9822
Disclosure Date: July 20, 2017 (last updated July 25, 2024)
DNN (aka DotNetNuke) before 9.1.1 has Remote Code Execution via a cookie, aka "2017-08 (Critical) Possible remote code execution on DNN sites."
0