PT-2009-6288 · Dnn · Dotnetnuke

Publicado

2009-11-28

·

Atualizado

2009-11-30

·

CVE-2009-4109

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions DotNetNuke versions 4.0 through 5.1.4
Description The issue allows remote attackers to access version information and possibly other sensitive information due to the install wizard not preventing anonymous users from accessing certain functionality.
Recommendations For versions 4.0 through 5.1.4, consider restricting access to the install wizard to prevent anonymous users from accessing sensitive information until a fix is available.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2009-4109

Produtos afetados

Dotnetnuke