CVE-2006-4973: XSS
Cross-site scripting (XSS) vulnerability in Default.aspx in Perpetual Motion Interactive Systems DotNetNuke before 3.3.5, and 4.x before 4.3.5, allows remote attackers to inject arbitrary HTML via the error parameter.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-4973?
CVE-2006-4973 is classified as a medium severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2006-4973?
To mitigate CVE-2006-4973, you should upgrade to DotNetNuke version 3.3.5 or later for version 3.x and to 4.3.5 or later for version 4.x.
Which versions of DotNetNuke are affected by CVE-2006-4973?
CVE-2006-4973 affects DotNetNuke versions prior to 3.3.5 for 3.x and prior to 4.3.5 for 4.x.
What type of vulnerability is CVE-2006-4973?
CVE-2006-4973 is a cross-site scripting (XSS) vulnerability that allows attackers to inject arbitrary HTML.
Who can exploit CVE-2006-4973?
CVE-2006-4973 can be exploited by remote attackers to execute malicious scripts in the context of a victim's session.