|
3571
|
- |
|
dnnsoftware
|
dotnetnuke
|
Vulnerabilidad sin especificar en DotNetNuke v4.0 a la v4.8.4 y 5.0, permite a usuarios autenticados remotamente evitar la autenticación y obtener privilegios a través de vectores desconocidos relac…
|
NVD-CWE-noinfo
|
CVE-2008-7100
|
2026-04-25 02:34 |
2009-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3572
|
- |
|
dnnsoftware
|
dotnetnuke
|
Unspecified vulnerability in DotNetNuke 4.0 through 4.8.4 and 5.0 allows remote attackers to obtain sensitive information (portal number) by accessing the install wizard page via unknown vectors.
|
NVD-CWE-noinfo
|
CVE-2008-7101
|
2026-04-25 02:34 |
2009-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3573
|
- |
|
dnnsoftware
|
dotnetnuke
|
Vulnerabilidad sin especificar en DotNetNuke v4.0 a la v4.8.4 y 5.0, permite a atacantes remotos obtener información sensible (número de portal) accediendo a la página del asistente de instalación me…
|
NVD-CWE-noinfo
|
CVE-2008-7101
|
2026-04-25 02:34 |
2009-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3574
|
- |
|
dnnsoftware
|
dotnetnuke
|
DotNetNuke 2.0 through 4.8.4 allows remote attackers to load .ascx files instead of skin files, and possibly access privileged functionality, via unknown vectors related to parameter validation.
|
CWE-20
Improper Input Validation
|
CVE-2008-7102
|
2026-04-25 02:34 |
2009-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3575
|
- |
|
dnnsoftware
|
dotnetnuke
|
DotNetNuke v2.0 hasta v4.8.4 permite a los atacantes remotos cargar archivos .ascx en lugar de un archivo de piel (skin), y posiblemente acceso privilegiado a funcionalidades, a través de vectores de…
|
CWE-20
Improper Input Validation
|
CVE-2008-7102
|
2026-04-25 02:34 |
2009-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3576
|
- |
|
dnnsoftware
|
dotnetnuke
|
The install wizard in DotNetNuke 4.0 through 5.1.4 does not prevent anonymous users from accessing functionality related to determination of the need for an upgrade, which allows remote attackers to …
|
CWE-200
Information Exposure
|
CVE-2009-4109
|
2026-04-25 02:34 |
2009-11-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3577
|
- |
|
dnnsoftware
|
dotnetnuke
|
El asistente de instalación en DotNetNuke v4.0 a la v5.1.4, no prevé el acceso de usuarios anónimos a la funcionalidad relacionada con la necesidad de una actualización, lo que permite a atacantes re…
|
CWE-200
Information Exposure
|
CVE-2009-4109
|
2026-04-25 02:34 |
2009-11-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3578
|
- |
|
dnnsoftware
|
dotnetnuke
|
Cross-site scripting (XSS) vulnerability in the search functionality in DotNetNuke 4.8 through 5.1.4 allows remote attackers to inject arbitrary web script or HTML via search terms that are not prope…
|
CWE-79
Cross-site Scripting
|
CVE-2009-4110
|
2026-04-25 02:34 |
2009-11-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3579
|
- |
|
dnnsoftware
|
dotnetnuke
|
Vulnerabilidad de ejecución de secuencias de comandos en sitios cruzados en la funcionalidad de búsqueda en DotNetNuke v4.8 a la v5.1.4, permite a atacantes remotos inyectar secuencias de comandos we…
|
CWE-79
Cross-site Scripting
|
CVE-2009-4110
|
2026-04-25 02:34 |
2009-11-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3580
|
- |
|
dnnsoftware
|
dotnetnuke
|
Cross-site scripting (XSS) vulnerability in Install/InstallWizard.aspx in DotNetNuke 5.05.01 and 5.06.00 allows remote attackers to inject arbitrary web script or HTML via the __VIEWSTATE parameter. …
|
CWE-79
Cross-site Scripting
|
CVE-2010-4514
|
2026-04-25 02:34 |
2010-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|