First published: Thu Mar 05 2009(Updated: )
Unspecified vulnerability in DotNetNuke 4.5.2 through 4.9 allows remote attackers to "add additional roles to their user account" via unknown attack vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
DNN (DotNetNuke) | =4.8.2 | |
DNN (DotNetNuke) | =4.8.1 | |
DNN (DotNetNuke) | =4.8.3 | |
DNN (DotNetNuke) | =4.5.2 | |
DNN (DotNetNuke) | =4.8.4 | |
DNN (DotNetNuke) | =4.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-6399 is considered a high severity vulnerability that allows unauthorized role assignment.
To fix CVE-2008-6399, upgrade to a patched version of DotNetNuke beyond version 4.9.
CVE-2008-6399 affects DotNetNuke versions 4.5.2 through 4.9.
CVE-2008-6399 enables attackers to add additional roles to their user accounts without proper authorization.
Yes, the exploitable nature of CVE-2008-6399 presents a significant risk of exploitation by remote attackers.