|
2101
|
5.0 |
MEDIUM
|
dnnsoftware
|
dotnetnuke
|
DotNetNuke (formerly IBuySpy Workshop) 1.0.6 through 1.0.10d allows remote attackers to obtain sensitive information, including the SQL server username and password, via a GET request for source or c…
|
NVD-CWE-Other
|
CVE-2004-2323
|
2026-04-25 02:34 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2102
|
7.5 |
HIGH
|
dnnsoftware
|
dotnetnuke
|
SQL injection vulnerability in DotNetNuke (formerly IBuySpy Workshop) 1.0.6 through 1.0.10d allows remote attackers to modify the backend database via the (1) table and (2) field parameters in LinkCl…
|
NVD-CWE-Other
|
CVE-2004-2324
|
2026-04-25 02:34 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2103
|
4.3 |
MEDIUM
|
dnnsoftware
|
dotnetnuke
|
Cross-site scripting (XSS) vulnerability in EditModule.aspx for DotNetNuke (formerly IBuySpy Workshop) 1.0.6 through 1.0.10d allows remote attackers to inject arbitrary web script or HTML.
|
NVD-CWE-Other
|
CVE-2004-2325
|
2026-04-25 02:34 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2104
|
4.3 |
MEDIUM
|
dnnsoftware
|
dotnetnuke
|
Multiple cross-site scripting (XSS) vulnerabilities in DotNetNuke before 3.0.12 allow remote attackers to inject arbitrary web script or HTML via the (1) register a new user page, (2) User-Agent, or …
|
NVD-CWE-Other
|
CVE-2005-0040
|
2026-04-25 02:34 |
2005-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2105
|
10.0 |
HIGH
|
dnnsoftware
|
dotnetnuke
|
** UNVERIFIABLE ** Unspecified vulnerability in an unspecified DNN Modules module for DotNetNuke (.net nuke) allows remote attackers to gain privileges via unspecified vectors, as used in an attack …
|
NVD-CWE-Other
|
CVE-2006-3601
|
2026-04-25 02:34 |
2006-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2106
|
10.0 |
HIGH
|
dnnsoftware
|
dotnetnuke
|
** NO VERIFICABLE ** Vulnerabilidad no especificada en en un módulo DNN Modules no especificado para DotNetNuke (.net nuke) permiten a atacantes remotos obtener privilegios mediante vectores no espec…
|
NVD-CWE-Other
|
CVE-2006-3601
|
2026-04-25 02:34 |
2006-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2107
|
4.3 |
MEDIUM
|
dnnsoftware
|
dotnetnuke
|
Cross-site scripting (XSS) vulnerability in Default.aspx in Perpetual Motion Interactive Systems DotNetNuke before 3.3.5, and 4.x before 4.3.5, allows remote attackers to inject arbitrary HTML via th…
|
NVD-CWE-Other
|
CVE-2006-4973
|
2026-04-25 02:34 |
2006-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2108
|
4.3 |
MEDIUM
|
dnnsoftware
|
dotnetnuke
|
Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en Default.aspx en Perpetual Motion Interactive Systems DotNetNuke anteriores a 3.3.5, y 4.x anteriores a 4.3.5, permite a un atacant…
|
NVD-CWE-Other
|
CVE-2006-4973
|
2026-04-25 02:34 |
2006-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2109
|
6.4 |
MEDIUM
|
dnnsoftware
|
dotnetnuke
|
Unspecified vulnerability in DotNetNuke 4.5.2 through 4.9 allows remote attackers to "add additional roles to their user account" via unknown attack vectors.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-6399
|
2026-04-25 02:34 |
2009-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2110
|
6.4 |
MEDIUM
|
dnnsoftware
|
dotnetnuke
|
Vulnerabilidad no especificada en DotNetNuke v4.5.2 hasta v4.9 permite a atacantes remotos "añadir reglas adicionales de sus cuentas de usuario" a través de vectores de ataque desconocidos.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-6399
|
2026-04-25 02:34 |
2009-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2111
|
5.1 |
MEDIUM
|
dnnsoftware
|
dotnetnuke
|
DotNetNuke before 4.8.2, during installation or upgrade, does not warn the administrator when the default (1) ValidationKey and (2) DecryptionKey values cannot be modified in the web.config file, whi…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-6540
|
2026-04-25 02:34 |
2009-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2112
|
5.1 |
MEDIUM
|
dnnsoftware
|
dotnetnuke
|
DotNetNuke anteriores a v4.8.2, durante la instalación o actualización, no avisan al administrador que los valores (1) ValidationKey y (2) DecryptionKey no pueden ser modificados en el fichero web.…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-6540
|
2026-04-25 02:34 |
2009-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2113
|
6.8 |
MEDIUM
|
dnnsoftware
|
dotnetnuke
|
Unrestricted file upload vulnerability in the file manager module in DotNetNuke before 4.8.2 allows remote administrators to upload arbitrary files and gain privileges to the server via unspecified v…
|
CWE-20
Improper Input Validation
|
CVE-2008-6541
|
2026-04-25 02:34 |
2009-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2114
|
6.8 |
MEDIUM
|
dnnsoftware
|
dotnetnuke
|
Vulnerabilidad de envío de archivo no restringido en el módulo de gestión en DotNetNuke anterior a v4.8.2, permite a administradores remotos la subida de archivos de su elección y la elevación de pri…
|
CWE-20
Improper Input Validation
|
CVE-2008-6541
|
2026-04-25 02:34 |
2009-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2115
|
4.6 |
MEDIUM
|
dnnsoftware
|
dotnetnuke
|
Unspecified vulnerability in the Skin Manager in DotNetNuke before 4.8.2 allows remote authenticated administrators to perform "server-side execution of application logic" by uploading a static file …
|
NVD-CWE-noinfo
|
CVE-2008-6542
|
2026-04-25 02:34 |
2009-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2116
|
4.6 |
MEDIUM
|
dnnsoftware
|
dotnetnuke
|
Vulnerabilidad no específica en Skin Manager en DotNetNuke anteriores a v4.8.2 permite a administradores autentificados remotos ejecutar una aplicación lógica desde el lado del servidor, subiendo un …
|
NVD-CWE-noinfo
|
CVE-2008-6542
|
2026-04-25 02:34 |
2009-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2117
|
4.3 |
MEDIUM
|
dnnsoftware
|
dotnetnuke
|
Cross-site scripting (XSS) vulnerability in Default.aspx in DotNetNuke 4.8.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.
|
CWE-79
Cross-site Scripting
|
CVE-2008-6644
|
2026-04-25 02:34 |
2009-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2118
|
4.3 |
MEDIUM
|
dnnsoftware
|
dotnetnuke
|
Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en Default.aspx en DotNetNuke v4.8.3 y anteriores permite a atacantes remotos inyectar secuencias de comandos web o HTML a traves de …
|
CWE-79
Cross-site Scripting
|
CVE-2008-6644
|
2026-04-25 02:34 |
2009-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2119
|
4.3 |
MEDIUM
|
dnnsoftware
|
dotnetnuke
|
Cross-site scripting (XSS) vulnerability in the Language skin object in DotNetNuke before 4.8.4 allows remote attackers to inject arbitrary web script or HTML via "newly generated paths."
|
CWE-79
Cross-site Scripting
|
CVE-2008-6732
|
2026-04-25 02:34 |
2009-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2120
|
4.3 |
MEDIUM
|
dnnsoftware
|
dotnetnuke
|
Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en el objeto "Language skin" en DotNetNuke anteriores a v4.8.4 permite a atacantes remotos inyectar secuencias de comando web o HTML …
|
CWE-79
Cross-site Scripting
|
CVE-2008-6732
|
2026-04-25 02:34 |
2009-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2121
|
4.3 |
MEDIUM
|
dnnsoftware
|
dotnetnuke
|
Cross-site scripting (XSS) vulnerability in the error handling page in DotNetNuke 4.6.2 through 4.8.3 allows remote attackers to inject arbitrary web script or HTML via the querystring parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2008-6733
|
2026-04-25 02:34 |
2009-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2122
|
4.3 |
MEDIUM
|
dnnsoftware
|
dotnetnuke
|
Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en la pagina de manejo de errores en DotNetNuke v4.6.2 hasta la v4.8.3 permite a atacantes remotos inyectar secuencias de comandos w…
|
CWE-79
Cross-site Scripting
|
CVE-2008-6733
|
2026-04-25 02:34 |
2009-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2123
|
4.3 |
MEDIUM
|
dnnsoftware
|
dotnetnuke
|
Cross-site scripting (XSS) vulnerability in Website\admin\Sales\paypalipn.aspx in DotNetNuke (DNN) before 4.9.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors …
|
CWE-79
Cross-site Scripting
|
CVE-2009-1366
|
2026-04-25 02:34 |
2009-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2124
|
4.3 |
MEDIUM
|
dnnsoftware
|
dotnetnuke
|
Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en Website\admin\Sales\paypalipn.aspx en DotNetNuke (DNN) versiones anteriores v4.9.3 permite a atacantes remotos inyectar secuencias…
|
CWE-79
Cross-site Scripting
|
CVE-2009-1366
|
2026-04-25 02:34 |
2009-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2125
|
6.5 |
MEDIUM
|
dnnsoftware
|
dotnetnuke
|
Unspecified vulnerability in DotNetNuke 4.4.1 through 4.8.4 allows remote authenticated users to bypass authentication and gain privileges via unknown vectors related to a "unique id" for user action…
|
NVD-CWE-noinfo
|
CVE-2008-7100
|
2026-04-25 02:34 |
2009-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2126
|
6.5 |
MEDIUM
|
dnnsoftware
|
dotnetnuke
|
Vulnerabilidad sin especificar en DotNetNuke v4.0 a la v4.8.4 y 5.0, permite a usuarios autenticados remotamente evitar la autenticación y obtener privilegios a través de vectores desconocidos relac…
|
NVD-CWE-noinfo
|
CVE-2008-7100
|
2026-04-25 02:34 |
2009-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2127
|
5.0 |
MEDIUM
|
dnnsoftware
|
dotnetnuke
|
Unspecified vulnerability in DotNetNuke 4.0 through 4.8.4 and 5.0 allows remote attackers to obtain sensitive information (portal number) by accessing the install wizard page via unknown vectors.
|
NVD-CWE-noinfo
|
CVE-2008-7101
|
2026-04-25 02:34 |
2009-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2128
|
5.0 |
MEDIUM
|
dnnsoftware
|
dotnetnuke
|
Vulnerabilidad sin especificar en DotNetNuke v4.0 a la v4.8.4 y 5.0, permite a atacantes remotos obtener información sensible (número de portal) accediendo a la página del asistente de instalación me…
|
NVD-CWE-noinfo
|
CVE-2008-7101
|
2026-04-25 02:34 |
2009-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2129
|
7.5 |
HIGH
|
dnnsoftware
|
dotnetnuke
|
DotNetNuke 2.0 through 4.8.4 allows remote attackers to load .ascx files instead of skin files, and possibly access privileged functionality, via unknown vectors related to parameter validation.
|
CWE-20
Improper Input Validation
|
CVE-2008-7102
|
2026-04-25 02:34 |
2009-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2130
|
7.5 |
HIGH
|
dnnsoftware
|
dotnetnuke
|
DotNetNuke v2.0 hasta v4.8.4 permite a los atacantes remotos cargar archivos .ascx en lugar de un archivo de piel (skin), y posiblemente acceso privilegiado a funcionalidades, a través de vectores de…
|
CWE-20
Improper Input Validation
|
CVE-2008-7102
|
2026-04-25 02:34 |
2009-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2131
|
5.0 |
MEDIUM
|
dnnsoftware
|
dotnetnuke
|
The install wizard in DotNetNuke 4.0 through 5.1.4 does not prevent anonymous users from accessing functionality related to determination of the need for an upgrade, which allows remote attackers to …
|
CWE-200
Information Exposure
|
CVE-2009-4109
|
2026-04-25 02:34 |
2009-11-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2132
|
5.0 |
MEDIUM
|
dnnsoftware
|
dotnetnuke
|
El asistente de instalación en DotNetNuke v4.0 a la v5.1.4, no prevé el acceso de usuarios anónimos a la funcionalidad relacionada con la necesidad de una actualización, lo que permite a atacantes re…
|
CWE-200
Information Exposure
|
CVE-2009-4109
|
2026-04-25 02:34 |
2009-11-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2133
|
4.3 |
MEDIUM
|
dnnsoftware
|
dotnetnuke
|
Cross-site scripting (XSS) vulnerability in the search functionality in DotNetNuke 4.8 through 5.1.4 allows remote attackers to inject arbitrary web script or HTML via search terms that are not prope…
|
CWE-79
Cross-site Scripting
|
CVE-2009-4110
|
2026-04-25 02:34 |
2009-11-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2134
|
4.3 |
MEDIUM
|
dnnsoftware
|
dotnetnuke
|
Vulnerabilidad de ejecución de secuencias de comandos en sitios cruzados en la funcionalidad de búsqueda en DotNetNuke v4.8 a la v5.1.4, permite a atacantes remotos inyectar secuencias de comandos we…
|
CWE-79
Cross-site Scripting
|
CVE-2009-4110
|
2026-04-25 02:34 |
2009-11-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2135
|
4.3 |
MEDIUM
|
dnnsoftware
|
dotnetnuke
|
Cross-site scripting (XSS) vulnerability in Install/InstallWizard.aspx in DotNetNuke 5.05.01 and 5.06.00 allows remote attackers to inject arbitrary web script or HTML via the __VIEWSTATE parameter. …
|
CWE-79
Cross-site Scripting
|
CVE-2010-4514
|
2026-04-25 02:34 |
2010-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2136
|
4.3 |
MEDIUM
|
dnnsoftware
|
dotnetnuke
|
Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en Install/InstallWizard.aspx en DotNetNuke 5.05.01 y 5.06.00 permite a atacantes remotos inyectar secuencias de comandos web o HTML …
|
CWE-79
Cross-site Scripting
|
CVE-2010-4514
|
2026-04-25 02:34 |
2010-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2137
|
4.3 |
MEDIUM
|
dnnsoftware
|
dotnetnuke
|
Cross-site scripting (XSS) vulnerability in DotNetNuke 6.x through 6.0.2 allows user-assisted remote attackers to inject arbitrary web script or HTML via a crafted URL containing text that is used wi…
|
CWE-79
Cross-site Scripting
|
CVE-2012-1030
|
2026-04-25 02:34 |
2012-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2138
|
4.3 |
MEDIUM
|
dnnsoftware
|
dotnetnuke
|
vulnerabilidad de ejecución de secuencias de comandos en sitios cruzados (XSS) en DotNetNuke v6.x hasta v6.0.2, permite a atacantes remotos asistidos por usuarios locales inyectar secuencias de coman…
|
CWE-79
Cross-site Scripting
|
CVE-2012-1030
|
2026-04-25 02:34 |
2012-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2139
|
4.3 |
MEDIUM
|
dnnsoftware dotnetnuke
|
dotnetnuke
|
Cross-site scripting (XSS) vulnerability in the telerik HTML editor in DotNetNuke before 5.6.4 and 6.x before 6.1.0 allows remote attackers to inject arbitrary web script or HTML via a message.
|
CWE-79
Cross-site Scripting
|
CVE-2012-1036
|
2026-04-25 02:34 |
2012-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2140
|
4.3 |
MEDIUM
|
dnnsoftware dotnetnuke
|
dotnetnuke
|
vulnerabilidad de ejecución de secuencias de comandos en sitios cruzados (XSS) en el editor HTML telerik en DotNetNuke anteriores a v5.6.4 y v6.x anteriores a v6.1.0, permite a atacantes remotos inye…
|
CWE-79
Cross-site Scripting
|
CVE-2012-1036
|
2026-04-25 02:34 |
2012-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2141
|
3.5 |
LOW
|
dnnsoftware
|
dotnetnuke
|
Cross-site scripting (XSS) vulnerability in DotNetNuke (DNN) before 6.2.9 and 7.x before 7.1.1 allows remote authenticated users to inject arbitrary web script or HTML via vectors related to the Disp…
|
CWE-79
Cross-site Scripting
|
CVE-2013-3943
|
2026-04-25 02:34 |
2014-03-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2142
|
3.5 |
LOW
|
dnnsoftware
|
dotnetnuke
|
Vulnerabilidad de XSS en DotNetNuke (DNN) anterior a 6.2.9 y 7.x anterior a 7.1.1 permite a usuarios remotos autenticados inyectar script Web o HTML arbitrarios a través de vectores relacionados con …
|
CWE-79
Cross-site Scripting
|
CVE-2013-3943
|
2026-04-25 02:34 |
2014-03-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2143
|
4.3 |
MEDIUM
|
dnnsoftware
|
dotnetnuke
|
Cross-site scripting (XSS) vulnerability in DotNetNuke (DNN) before 6.2.9 and 7.x before 7.1.1 allows remote attackers to inject arbitrary web script or HTML via the __dnnVariable parameter to the de…
|
CWE-79
Cross-site Scripting
|
CVE-2013-4649
|
2026-04-25 02:34 |
2014-03-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2144
|
4.3 |
MEDIUM
|
dnnsoftware
|
dotnetnuke
|
Vulnerabilidad de XSS en DotNetNuke (DNN) anterior a 6.2.9 y 7.x anterior a 7.1.1 permite a atacantes remotos inyectar script Web o HTML arbitrarios a través del parámetro __dnnVariable hacia la URI …
|
CWE-79
Cross-site Scripting
|
CVE-2013-4649
|
2026-04-25 02:34 |
2014-03-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2145
|
4.3 |
MEDIUM
|
dnnsoftware
|
dotnetnuke
|
Open redirect vulnerability in DotNetNuke (DNN) before 6.2.9 and 7.x before 7.1.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
|
CWE-20
Improper Input Validation
|
CVE-2013-7335
|
2026-04-25 02:34 |
2014-03-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2146
|
4.3 |
MEDIUM
|
dnnsoftware
|
dotnetnuke
|
Vulnerabilidad de redirección abierta en DotNetNuke (DNN) anterior a 6.2.9 y 7.x anterior a 7.1.1 permite a atacantes remotos redirigir usuarios hacia sitios web arbitrarios y realizar ataques de phi…
|
CWE-20
Improper Input Validation
|
CVE-2013-7335
|
2026-04-25 02:34 |
2014-03-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2147
|
4.3 |
MEDIUM
|
dnnsoftware
|
dotnetnuke
|
Cross-site scripting (XSS) vulnerability in DotNetNuke (DNN) before 7.4.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2015-1566
|
2026-04-25 02:34 |
2015-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2148
|
4.3 |
MEDIUM
|
dnnsoftware
|
dotnetnuke
|
Vulnerabilidad de XSS en DotNetNuke (DNN) anterior a 7.4.0 permite a atacantes remotos inyectar secuencias de comandos web arbitrarios o HTML a través de vectores no especificados.
|
CWE-79
Cross-site Scripting
|
CVE-2015-1566
|
2026-04-25 02:34 |
2015-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2149
|
5.4 |
MEDIUM
Network
|
dnnsoftware
|
dotnetnuke
|
Cross-site scripting (XSS) vulnerability in the user-profile biography section in DotNetNuke (DNN) before 8.0.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted …
|
CWE-79
Cross-site Scripting
|
CVE-2016-7119
|
2026-04-25 02:34 |
2016-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2150
|
5.4 |
MEDIUM
Network
|
dnnsoftware
|
dotnetnuke
|
Vulnerabilidad de XSS en la sección de biografía del perfil del usuario en DotNetNuke (DNN) en versiones anteriores a 8.0.1 permite a usuarios remotos autenticados inyectar secuencias de comandos web…
|
CWE-79
Cross-site Scripting
|
CVE-2016-7119
|
2026-04-25 02:34 |
2016-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|