PT-2006-5716 · Perpetual Motion Interactive Systems · Dotnetnuke

Published

2006-09-25

·

Updated

2024-02-14

·

CVE-2006-4973

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Perpetual Motion Interactive Systems DotNetNuke versions prior to 3.3.5 Perpetual Motion Interactive Systems DotNetNuke versions 4.x prior to 4.3.5
Description A cross-site scripting issue allows remote attackers to inject arbitrary HTML via the error parameter in the Default.aspx file.
Recommendations For versions prior to 3.3.5, update to version 3.3.5 or later. For versions 4.x prior to 4.3.5, update to version 4.3.5 or later.

Exploit

Fix

Related Identifiers

CVE-2006-4973

Affected Products

Dotnetnuke