This CPE summary could be partial or incomplete. Please contact us for a detailed listing.

Summary

Detail
Vendor Dotnetnuke First view 2004-12-31
Product Dotnetnuke Last view 2017-02-06
Version Type Application
Update  
Edition  
Language  
Sofware Edition  
Target Software  
Target Hardware  
Other  

Activity : Overall

COMMON PLATFORM ENUMERATION: Repartition per Version

CPE Name Affected CVE
cpe:2.3:a:dotnetnuke:dotnetnuke:4.8.1:*:*:*:*:*:*:* 20
cpe:2.3:a:dotnetnuke:dotnetnuke:1.0.9:*:*:*:*:*:*:* 18
cpe:2.3:a:dotnetnuke:dotnetnuke:4.5.2:*:*:*:*:*:*:* 18
cpe:2.3:a:dotnetnuke:dotnetnuke:1.0.6:*:*:*:*:*:*:* 18
cpe:2.3:a:dotnetnuke:dotnetnuke:1.0.8:*:*:*:*:*:*:* 18
cpe:2.3:a:dotnetnuke:dotnetnuke:4.6.2:*:*:*:*:*:*:* 18
cpe:2.3:a:dotnetnuke:dotnetnuke:1.0.10d:*:*:*:*:*:*:* 18
cpe:2.3:a:dotnetnuke:dotnetnuke:1.0.7:*:*:*:*:*:*:* 18
cpe:2.3:a:dotnetnuke:dotnetnuke:4.8.0:*:*:*:*:*:*:* 18
cpe:2.3:a:dotnetnuke:dotnetnuke:4.4.1:*:*:*:*:*:*:* 17
cpe:2.3:a:dotnetnuke:dotnetnuke:4.6.1:*:*:*:*:*:*:* 17
cpe:2.3:a:dotnetnuke:dotnetnuke:4.0:*:*:*:*:*:*:* 17
cpe:2.3:a:dotnetnuke:dotnetnuke:4.8.2:*:*:*:*:*:*:* 17
cpe:2.3:a:dotnetnuke:dotnetnuke:4.8.3:*:*:*:*:*:*:* 17
cpe:2.3:a:dotnetnuke:dotnetnuke:4.5.4:*:*:*:*:*:*:* 17
cpe:2.3:a:dotnetnuke:dotnetnuke:4.7.0:*:*:*:*:*:*:* 17
cpe:2.3:a:dotnetnuke:dotnetnuke:4.5.5:*:*:*:*:*:*:* 17
cpe:2.3:a:dotnetnuke:dotnetnuke:4.6.0:*:*:*:*:*:*:* 17
cpe:2.3:a:dotnetnuke:dotnetnuke:3.0.7:*:*:*:*:*:*:* 16
cpe:2.3:a:dotnetnuke:dotnetnuke:2.1.1:*:*:*:*:*:*:* 16
cpe:2.3:a:dotnetnuke:dotnetnuke:2.1.2:*:*:*:*:*:*:* 16
cpe:2.3:a:dotnetnuke:dotnetnuke:3.0.8:*:*:*:*:*:*:* 16
cpe:2.3:a:dotnetnuke:dotnetnuke:4.3.5:*:*:*:*:*:*:* 16
cpe:2.3:a:dotnetnuke:dotnetnuke:3.0.11:*:*:*:*:*:*:* 15
cpe:2.3:a:dotnetnuke:dotnetnuke:3.1.0:*:*:*:*:*:*:* 15
cpe:2.3:a:dotnetnuke:dotnetnuke:*:*:*:*:*:*:*:* 15
cpe:2.3:a:dotnetnuke:dotnetnuke:1.0.10e:*:*:*:*:*:*:* 15
cpe:2.3:a:dotnetnuke:dotnetnuke:4.8.4:*:*:*:*:*:*:* 14
cpe:2.3:a:dotnetnuke:dotnetnuke:3.3.5:*:*:*:*:*:*:* 14
cpe:2.3:a:dotnetnuke:dotnetnuke:4.9:*:*:*:*:*:*:* 11
cpe:2.3:a:dotnetnuke:dotnetnuke:4.9.2:*:*:*:*:*:*:* 10
cpe:2.3:a:dotnetnuke:dotnetnuke:4.9.1:*:*:*:*:*:*:* 10
cpe:2.3:a:dotnetnuke:dotnetnuke:5.0:*:*:*:*:*:*:* 10
cpe:2.3:a:dotnetnuke:dotnetnuke:5.1.2:*:*:*:*:*:*:* 9
cpe:2.3:a:dotnetnuke:dotnetnuke:5.1.3:*:*:*:*:*:*:* 9
cpe:2.3:a:dotnetnuke:dotnetnuke:5.1.4:*:*:*:*:*:*:* 9
cpe:2.3:a:dotnetnuke:dotnetnuke:5.1:*:*:*:*:*:*:* 9
cpe:2.3:a:dotnetnuke:dotnetnuke:5.1.1:*:*:*:*:*:*:* 9
cpe:2.3:a:dotnetnuke:dotnetnuke:5.05.01:*:*:*:*:*:*:* 8
cpe:2.3:a:dotnetnuke:dotnetnuke:6.0.2:*:*:*:*:*:*:* 8
cpe:2.3:a:dotnetnuke:dotnetnuke:4.9.0:*:*:*:*:*:*:* 8
cpe:2.3:a:dotnetnuke:dotnetnuke:6.0.1:*:*:*:*:*:*:* 8
cpe:2.3:a:dotnetnuke:dotnetnuke:6.0.0:*:*:*:*:*:*:* 8
cpe:2.3:a:dotnetnuke:dotnetnuke:5.06.00:*:*:*:*:*:*:* 8
cpe:2.3:a:dotnetnuke:dotnetnuke:5.2.2:*:*:*:*:*:*:* 7
cpe:2.3:a:dotnetnuke:dotnetnuke:5.0.0:*:*:*:*:*:*:* 7
cpe:2.3:a:dotnetnuke:dotnetnuke:4.9.4:*:*:*:*:*:*:* 7
cpe:2.3:a:dotnetnuke:dotnetnuke:5.4.1:*:*:*:*:*:*:* 7
cpe:2.3:a:dotnetnuke:dotnetnuke:5.5.1:*:*:*:*:*:*:* 7
cpe:2.3:a:dotnetnuke:dotnetnuke:5.0.1:*:*:*:*:*:*:* 7

Related : CVE

This CPE Product have more than 25 Relations. If you want to see a complete summary for this CPE, please contact us.
  Date Alert Description
9.8 2017-02-06 CVE-2015-2794

The installation wizard in DotNetNuke (DNN) before 7.4.1 allows remote attackers to reinstall the application and gain SuperUser access via a direct request to Install/InstallWizard.aspx.

5.4 2016-08-31 CVE-2016-7119

Cross-site scripting (XSS) vulnerability in the user-profile biography section in DotNetNuke (DNN) before 8.0.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted onclick attribute in an IMG element.

4.3 2015-02-09 CVE-2015-1566

Cross-site scripting (XSS) vulnerability in DotNetNuke (DNN) before 7.4.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

4.3 2014-03-12 CVE-2013-7335

Open redirect vulnerability in DotNetNuke (DNN) before 6.2.9 and 7.x before 7.1.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

4.3 2014-03-12 CVE-2013-4649

Cross-site scripting (XSS) vulnerability in DotNetNuke (DNN) before 6.2.9 and 7.x before 7.1.1 allows remote attackers to inject arbitrary web script or HTML via the __dnnVariable parameter to the default URI.

3.5 2014-03-12 CVE-2013-3943

Cross-site scripting (XSS) vulnerability in DotNetNuke (DNN) before 6.2.9 and 7.x before 7.1.1 allows remote authenticated users to inject arbitrary web script or HTML via vectors related to the Display Name field in the Manage Profile.

4.3 2012-04-11 CVE-2012-1036

Cross-site scripting (XSS) vulnerability in the telerik HTML editor in DotNetNuke before 5.6.4 and 6.x before 6.1.0 allows remote attackers to inject arbitrary web script or HTML via a message.

4.3 2012-04-11 CVE-2012-1030

Cross-site scripting (XSS) vulnerability in DotNetNuke 6.x through 6.0.2 allows user-assisted remote attackers to inject arbitrary web script or HTML via a crafted URL containing text that is used within a modal popup.

4.3 2010-12-09 CVE-2010-4514

Cross-site scripting (XSS) vulnerability in Install/InstallWizard.aspx in DotNetNuke 5.05.01 and 5.06.00 allows remote attackers to inject arbitrary web script or HTML via the __VIEWSTATE parameter. NOTE: some of these details are obtained from third party information.

4.3 2009-11-29 CVE-2009-4110

Cross-site scripting (XSS) vulnerability in the search functionality in DotNetNuke 4.8 through 5.1.4 allows remote attackers to inject arbitrary web script or HTML via search terms that are not properly filtered before display in a custom results page.

5 2009-11-29 CVE-2009-4109

The install wizard in DotNetNuke 4.0 through 5.1.4 does not prevent anonymous users from accessing functionality related to determination of the need for an upgrade, which allows remote attackers to access version information and possibly other sensitive information.

7.5 2009-08-27 CVE-2008-7102

DotNetNuke 2.0 through 4.8.4 allows remote attackers to load .ascx files instead of skin files, and possibly access privileged functionality, via unknown vectors related to parameter validation.

5 2009-08-27 CVE-2008-7101

Unspecified vulnerability in DotNetNuke 4.0 through 4.8.4 and 5.0 allows remote attackers to obtain sensitive information (portal number) by accessing the install wizard page via unknown vectors.

6.5 2009-08-27 CVE-2008-7100

Unspecified vulnerability in DotNetNuke 4.4.1 through 4.8.4 allows remote authenticated users to bypass authentication and gain privileges via unknown vectors related to a "unique id" for user actions and improper validation of a "user identity."

4.3 2009-04-22 CVE-2009-1366

Cross-site scripting (XSS) vulnerability in Website\admin\Sales\paypalipn.aspx in DotNetNuke (DNN) before 4.9.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to "name/value pairs" and "paypal IPN functionality."

4.3 2009-04-21 CVE-2008-6733

Cross-site scripting (XSS) vulnerability in the error handling page in DotNetNuke 4.6.2 through 4.8.3 allows remote attackers to inject arbitrary web script or HTML via the querystring parameter.

4.3 2009-04-21 CVE-2008-6732

Cross-site scripting (XSS) vulnerability in the Language skin object in DotNetNuke before 4.8.4 allows remote attackers to inject arbitrary web script or HTML via "newly generated paths."

4.3 2009-04-07 CVE-2008-6644

Cross-site scripting (XSS) vulnerability in Default.aspx in DotNetNuke 4.8.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.

4.6 2009-03-29 CVE-2008-6542

Unspecified vulnerability in the Skin Manager in DotNetNuke before 4.8.2 allows remote authenticated administrators to perform "server-side execution of application logic" by uploading a static file that is converted into a dynamic script via unknown vectors related to HTM or HTML files.

6.8 2009-03-29 CVE-2008-6541

Unrestricted file upload vulnerability in the file manager module in DotNetNuke before 4.8.2 allows remote administrators to upload arbitrary files and gain privileges to the server via unspecified vectors.

5.1 2009-03-29 CVE-2008-6540

DotNetNuke before 4.8.2, during installation or upgrade, does not warn the administrator when the default (1) ValidationKey and (2) DecryptionKey values cannot be modified in the web.config file, which allows remote attackers to bypass intended access restrictions by using the default keys.

6.4 2009-03-05 CVE-2008-6399

Unspecified vulnerability in DotNetNuke 4.5.2 through 4.9 allows remote attackers to "add additional roles to their user account" via unknown attack vectors.

4.3 2006-09-24 CVE-2006-4973

Cross-site scripting (XSS) vulnerability in Default.aspx in Perpetual Motion Interactive Systems DotNetNuke before 3.3.5, and 4.x before 4.3.5, allows remote attackers to inject arbitrary HTML via the error parameter.

10 2006-07-18 CVE-2006-3601

** UNVERIFIABLE ** Unspecified vulnerability in an unspecified DNN Modules module for DotNetNuke (.net nuke) allows remote attackers to gain privileges via unspecified vectors, as used in an attack against the Microsoft France web site. NOTE: due to the lack of details and uncertainty about which product is affected, this claim is not independently verifiable.

4.3 2005-05-19 CVE-2005-0040

Multiple cross-site scripting (XSS) vulnerabilities in DotNetNuke before 3.0.12 allow remote attackers to inject arbitrary web script or HTML via the (1) register a new user page, (2) User-Agent, or (3) Username, which is not properly quoted before sending to the error log.

CWE : Common Weakness Enumeration

%idName
63% (12) CWE-79 Failure to Preserve Web Page Structure ('Cross-site Scripting')
15% (3) CWE-264 Permissions, Privileges, and Access Controls
15% (3) CWE-20 Improper Input Validation
5% (1) CWE-200 Information Exposure

Open Source Vulnerability Database (OSVDB)

id Description
69686 DotNetNuke Install/InstallWizard.aspx __VIEWSTATE Parameter XSS
60520 DotNetNuke Install Wizard Remote Information Disclosure
60519 DotNetNuke Search Functionality Unspecified XSS
53616 DotNetNuke Website\admin\Sales\paypalipn.aspx Unspecified Parameter XSS
51141 DotNetNuke Unspecified Privilege Escalation
48345 DotNetNuke Skin Handling Arbitrary ascx File Load Security Bypass
48344 DotNetNuke Install Wizard Page Portal Number Disclosure
48343 DotNetNuke Unspecified Remote Privilege Escalation
46323 DotNetNuke Error Handling Page Query String XSS
46322 DotNetNuke Language Skin Object XSS
45857 DotNetNuke Default.aspx URL XSS
43721 DotNetNuke Admin Skin Management File Upload Arbitrary Code Execution
43720 DotNetNuke Upgrade Process validationkey Generation Weakness Privilege Escala...
43719 DotNetNuke File Manager Module File Upload Restriction Bypass
41851 BDPDT for DotNetNuke (.net nuke) uploadfilepopup.aspx File Upload Privilege E...
29044 DotNetNuke error Parameter XSS
16616 DotNetNuke Username Field Log Viewer XSS
16615 DotNetNuke User-Agent String XSS
16614 DotNetNuke New User Registration XSS
3751 DotNetNuke editModule.aspx XSS
3750 DotNetNuke LinkClick.aspx Multiple Field SQL Injection
3749 DotNetNuke Web.config SQL Server Auth Credential Disclosure

OpenVAS Exploits

id Description
2011-05-11 Name : DotNetNuke 'InstallWizard.aspx' Cross Site Scripting Vulnerability
File : nvt/secpod_dotnetnuke_installwizard_xss_vuln.nasl
2009-12-02 Name : DotNetNuke Information Disclosure Vulnerability
File : nvt/gb_dotnetnuke_info_disc_vuln.nasl
2009-12-02 Name : DotNetNuke Cross Site Scripting Vulnerability
File : nvt/gb_dotnetnuke_xss_search_vuln.nasl
2009-09-03 Name : DotNetNuke Identity Authentication Bypass Vulnerability
File : nvt/gb_dotnetnuke_auth_bypass_vuln.nasl
2009-09-03 Name : DotNetNuke Install Wizard Information Disclosure Vulnerability
File : nvt/gb_dotnetnuke_installwizard_info_disc_vuln.nasl
2009-09-03 Name : DotNetNuke Skin Files Security Bypass Vulnerability
File : nvt/gb_dotnetnuke_skin_sec_bypass_vuln.nasl
2005-11-03 Name : Multiple DotNetNuke HTML Injection Vulnerabilities
File : nvt/dotnetnuke_xss.nasl

Information Assurance Vulnerability Management (IAVM)

id Description
2015-B-0021 DotNetNuke Cross-Site Scripting Vulnerability
Severity: Category I - VMSKEY: V0058763
2013-B-0090 Multiple Vulnerabilities in DotNetNuke
Severity: Category I - VMSKEY: V0040109

Snort® IPS/IDS

Date Description
2017-02-23 DotNetNuke installation attempt detected
RuleID : 41713-community - Type : SERVER-WEBAPP - Revision : 2
2017-03-28 DotNetNuke installation attempt detected
RuleID : 41713 - Type : SERVER-WEBAPP - Revision : 2

Nessus® Vulnerability Scanner

id Description
2017-06-20 Name: An application running on the remote web server is affected by an authenticat...
File: dotnetnuke_7_4_1.nasl - Type: ACT_GATHER_INFO
2015-02-12 Name: The remote web server contains an ASP.NET application that is affected by a c...
File: dotnetnuke_7_4_0.nasl - Type: ACT_GATHER_INFO
2013-10-03 Name: The remote web server contains an ASP.NET application that is affected by mul...
File: dotnetnuke_6_2_9.nasl - Type: ACT_GATHER_INFO
2013-08-16 Name: The remote web server contains an ASP.NET application that is affected by a c...
File: dotnetnuke_dnnvariable_xss.nasl - Type: ACT_ATTACK
2010-03-22 Name: The remote web server contains an ASP.NET application that is affected by a c...
File: dotnetnuke_search_page_xss_5_3_0.nasl - Type: ACT_ATTACK
2009-12-02 Name: The remote web server contains a ASP.NET application that is affected by a cr...
File: dotnetnuke_search_page_xss.nasl - Type: ACT_ATTACK
2008-03-25 Name: The remote web server contains an ASP.NET application that allows a remote at...
File: dotnetnuke_default_machine_key.nasl - Type: ACT_ATTACK
2006-06-23 Name: The remote web server contains an ASP script that allows uploading of arbitra...
File: bdpdt_cmd_exec.nasl - Type: ACT_ATTACK
2005-06-16 Name: The remote host contains an ASP application that is affected by multiple inpu...
File: dotnetnuke_xss.nasl - Type: ACT_GATHER_INFO