PT-2007-2114 · Dotnetnuke · Dotnetnuke Iframe Module

Published

2007-02-01

·

Updated

2022-05-01

·

CVE-2007-0660

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions DotNetNuke (DNN) IFrame module versions prior to 03.02.01
Description The issue is related to a cross-site scripting (XSS) vulnerability caused by improper validation of user-supplied input. This allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to "Pass through values." A remote attacker could exploit this vulnerability using various parameters in a specially-crafted URL to execute script in a victim's Web browser within the security context of the hosting Web site, once the URL is clicked. This could be used to steal the victim's cookie-based authentication credentials.
Recommendations For DotNetNuke (DNN) IFrame module versions prior to 03.02.01, update to version 03.02.01 or later to resolve the issue. As a temporary workaround, consider restricting the use of the IFrame module until a patch is applied. Avoid using the module with untrusted input to minimize the risk of exploitation.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2007-0660
GHSA-XR96-7CCP-PG5C

Affected Products

Dotnetnuke Iframe Module