CVE-2008-6399: Medium severity DotNetNuke DotNetNuke vulnerability
Published Mar 5, 2009
·Updated
Unspecified vulnerability in DotNetNuke 4.5.2 through 4.9 allows remote attackers to "add additional roles to their user account" via unknown attack vectors.
Affected Software
12 affected components
DotNetNuke DotNetNuke=4.8.2
DotNetNuke DotNetNuke=4.8.1
DotNetNuke DotNetNuke=4.8.3
DotNetNuke DotNetNuke=4.5.2
DotNetNuke DotNetNuke=4.8.4
DotNetNuke DotNetNuke=4.9
dnnsoftware Dotnetnuke=4.5.2
dnnsoftware Dotnetnuke=4.8.1
dnnsoftware Dotnetnuke=4.8.2
dnnsoftware Dotnetnuke=4.8.3
dnnsoftware Dotnetnuke=4.8.4
dnnsoftware Dotnetnuke=4.9
Event History
Mar 5, 2009
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Data Sourced
via NVD·08:30 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2008-6399?
CVE-2008-6399 is considered a high severity vulnerability that allows unauthorized role assignment.
2
How do I fix CVE-2008-6399?
To fix CVE-2008-6399, upgrade to a patched version of DotNetNuke beyond version 4.9.
3
What versions of DotNetNuke are affected by CVE-2008-6399?
CVE-2008-6399 affects DotNetNuke versions 4.5.2 through 4.9.
4
What type of attack does CVE-2008-6399 enable?
CVE-2008-6399 enables attackers to add additional roles to their user accounts without proper authorization.
5
Is there a risk of CVE-2008-6399 being exploited in the wild?
Yes, the exploitable nature of CVE-2008-6399 presents a significant risk of exploitation by remote attackers.