PT-2004-3217 · Dnn · Dotnetnuke
Published
2004-12-31
·
Updated
2017-07-11
·
CVE-2004-2323
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
DotNetNuke versions 1.0.6 through 1.0.10d
Description:
The issue allows remote attackers to obtain sensitive information, including the SQL server username and password, via a GET request for source or configuration files such as Web.config.
Recommendations:
For versions 1.0.6 through 1.0.10d, restrict access to configuration files like Web.config to prevent unauthorized disclosure of sensitive information.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Dotnetnuke