|
4431
|
- |
|
dnnsoftware
|
dotnetnuke
|
El asistente de instalación en DotNetNuke v4.0 a la v5.1.4, no prevé el acceso de usuarios anónimos a la funcionalidad relacionada con la necesidad de una actualización, lo que permite a atacantes re…
|
CWE-200
Information Exposure
|
CVE-2009-4109
|
2026-04-25 02:34 |
2009-11-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4432
|
- |
|
dnnsoftware
|
dotnetnuke
|
Cross-site scripting (XSS) vulnerability in the search functionality in DotNetNuke 4.8 through 5.1.4 allows remote attackers to inject arbitrary web script or HTML via search terms that are not prope…
|
CWE-79
Cross-site Scripting
|
CVE-2009-4110
|
2026-04-25 02:34 |
2009-11-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4433
|
- |
|
dnnsoftware
|
dotnetnuke
|
Vulnerabilidad de ejecución de secuencias de comandos en sitios cruzados en la funcionalidad de búsqueda en DotNetNuke v4.8 a la v5.1.4, permite a atacantes remotos inyectar secuencias de comandos we…
|
CWE-79
Cross-site Scripting
|
CVE-2009-4110
|
2026-04-25 02:34 |
2009-11-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4434
|
- |
|
dnnsoftware
|
dotnetnuke
|
Cross-site scripting (XSS) vulnerability in Install/InstallWizard.aspx in DotNetNuke 5.05.01 and 5.06.00 allows remote attackers to inject arbitrary web script or HTML via the __VIEWSTATE parameter. …
|
CWE-79
Cross-site Scripting
|
CVE-2010-4514
|
2026-04-25 02:34 |
2010-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4435
|
- |
|
dnnsoftware
|
dotnetnuke
|
Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en Install/InstallWizard.aspx en DotNetNuke 5.05.01 y 5.06.00 permite a atacantes remotos inyectar secuencias de comandos web o HTML …
|
CWE-79
Cross-site Scripting
|
CVE-2010-4514
|
2026-04-25 02:34 |
2010-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4436
|
- |
|
dnnsoftware
|
dotnetnuke
|
Cross-site scripting (XSS) vulnerability in DotNetNuke 6.x through 6.0.2 allows user-assisted remote attackers to inject arbitrary web script or HTML via a crafted URL containing text that is used wi…
|
CWE-79
Cross-site Scripting
|
CVE-2012-1030
|
2026-04-25 02:34 |
2012-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4437
|
- |
|
dnnsoftware
|
dotnetnuke
|
vulnerabilidad de ejecución de secuencias de comandos en sitios cruzados (XSS) en DotNetNuke v6.x hasta v6.0.2, permite a atacantes remotos asistidos por usuarios locales inyectar secuencias de coman…
|
CWE-79
Cross-site Scripting
|
CVE-2012-1030
|
2026-04-25 02:34 |
2012-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4438
|
- |
|
dnnsoftware dotnetnuke
|
dotnetnuke
|
Cross-site scripting (XSS) vulnerability in the telerik HTML editor in DotNetNuke before 5.6.4 and 6.x before 6.1.0 allows remote attackers to inject arbitrary web script or HTML via a message.
|
CWE-79
Cross-site Scripting
|
CVE-2012-1036
|
2026-04-25 02:34 |
2012-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4439
|
- |
|
dnnsoftware dotnetnuke
|
dotnetnuke
|
vulnerabilidad de ejecución de secuencias de comandos en sitios cruzados (XSS) en el editor HTML telerik en DotNetNuke anteriores a v5.6.4 y v6.x anteriores a v6.1.0, permite a atacantes remotos inye…
|
CWE-79
Cross-site Scripting
|
CVE-2012-1036
|
2026-04-25 02:34 |
2012-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4440
|
- |
|
dnnsoftware
|
dotnetnuke
|
Cross-site scripting (XSS) vulnerability in DotNetNuke (DNN) before 6.2.9 and 7.x before 7.1.1 allows remote authenticated users to inject arbitrary web script or HTML via vectors related to the Disp…
|
CWE-79
Cross-site Scripting
|
CVE-2013-3943
|
2026-04-25 02:34 |
2014-03-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|