CVE-2004-2323: Medium severity dotnetnuke dotnetnuke vulnerability
DotNetNuke (formerly IBuySpy Workshop) 1.0.6 through 1.0.10d allows remote attackers to obtain sensitive information, including the SQL server username and password, via a GET request for source or configuration files such as Web.config.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2004-2323?
CVE-2004-2323 is considered a high severity vulnerability due to the potential exposure of sensitive information including SQL server credentials.
How do I fix CVE-2004-2323?
To fix CVE-2004-2323, upgrade to a patched version of DotNetNuke that does not expose configuration files through GET requests.
What products are affected by CVE-2004-2323?
CVE-2004-2323 affects DotNetNuke versions 1.0.6 through 1.0.10d.
How does CVE-2004-2323 affect web application security?
CVE-2004-2323 compromises web application security by allowing attackers to access sensitive configuration files through simple GET requests.
Can CVE-2004-2323 be exploited remotely?
Yes, CVE-2004-2323 can be exploited remotely by attackers who attempt to access specific source or configuration files.