|
3991
|
- |
|
dnnsoftware
|
dotnetnuke
|
Vulnerabilidad no especificada en DotNetNuke v4.5.2 hasta v4.9 permite a atacantes remotos "añadir reglas adicionales de sus cuentas de usuario" a través de vectores de ataque desconocidos.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-6399
|
2026-04-25 02:34 |
2009-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3992
|
- |
|
dnnsoftware
|
dotnetnuke
|
DotNetNuke before 4.8.2, during installation or upgrade, does not warn the administrator when the default (1) ValidationKey and (2) DecryptionKey values cannot be modified in the web.config file, whi…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-6540
|
2026-04-25 02:34 |
2009-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3993
|
- |
|
dnnsoftware
|
dotnetnuke
|
DotNetNuke anteriores a v4.8.2, durante la instalación o actualización, no avisan al administrador que los valores (1) ValidationKey y (2) DecryptionKey no pueden ser modificados en el fichero web.…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-6540
|
2026-04-25 02:34 |
2009-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3994
|
- |
|
dnnsoftware
|
dotnetnuke
|
Unrestricted file upload vulnerability in the file manager module in DotNetNuke before 4.8.2 allows remote administrators to upload arbitrary files and gain privileges to the server via unspecified v…
|
CWE-20
Improper Input Validation
|
CVE-2008-6541
|
2026-04-25 02:34 |
2009-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3995
|
- |
|
dnnsoftware
|
dotnetnuke
|
Vulnerabilidad de envío de archivo no restringido en el módulo de gestión en DotNetNuke anterior a v4.8.2, permite a administradores remotos la subida de archivos de su elección y la elevación de pri…
|
CWE-20
Improper Input Validation
|
CVE-2008-6541
|
2026-04-25 02:34 |
2009-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3996
|
- |
|
dnnsoftware
|
dotnetnuke
|
Unspecified vulnerability in the Skin Manager in DotNetNuke before 4.8.2 allows remote authenticated administrators to perform "server-side execution of application logic" by uploading a static file …
|
NVD-CWE-noinfo
|
CVE-2008-6542
|
2026-04-25 02:34 |
2009-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3997
|
- |
|
dnnsoftware
|
dotnetnuke
|
Vulnerabilidad no específica en Skin Manager en DotNetNuke anteriores a v4.8.2 permite a administradores autentificados remotos ejecutar una aplicación lógica desde el lado del servidor, subiendo un …
|
NVD-CWE-noinfo
|
CVE-2008-6542
|
2026-04-25 02:34 |
2009-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3998
|
- |
|
dnnsoftware
|
dotnetnuke
|
Cross-site scripting (XSS) vulnerability in Default.aspx in DotNetNuke 4.8.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.
|
CWE-79
Cross-site Scripting
|
CVE-2008-6644
|
2026-04-25 02:34 |
2009-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3999
|
- |
|
dnnsoftware
|
dotnetnuke
|
Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en Default.aspx en DotNetNuke v4.8.3 y anteriores permite a atacantes remotos inyectar secuencias de comandos web o HTML a traves de …
|
CWE-79
Cross-site Scripting
|
CVE-2008-6644
|
2026-04-25 02:34 |
2009-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4000
|
- |
|
dnnsoftware
|
dotnetnuke
|
Cross-site scripting (XSS) vulnerability in the Language skin object in DotNetNuke before 4.8.4 allows remote attackers to inject arbitrary web script or HTML via "newly generated paths."
|
CWE-79
Cross-site Scripting
|
CVE-2008-6732
|
2026-04-25 02:34 |
2009-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|