First published: Thu Aug 27 2009(Updated: )
Unspecified vulnerability in DotNetNuke 4.4.1 through 4.8.4 allows remote authenticated users to bypass authentication and gain privileges via unknown vectors related to a "unique id" for user actions and improper validation of a "user identity."
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
DNN (DotNetNuke) | =4.4.1 | |
DNN (DotNetNuke) | =4.5.2 | |
DNN (DotNetNuke) | =4.5.4 | |
DNN (DotNetNuke) | =4.5.5 | |
DNN (DotNetNuke) | =4.6.0 | |
DNN (DotNetNuke) | =4.6.1 | |
DNN (DotNetNuke) | =4.6.2 | |
DNN (DotNetNuke) | =4.7.0 | |
DNN (DotNetNuke) | =4.8.0 | |
DNN (DotNetNuke) | =4.8.1 | |
DNN (DotNetNuke) | =4.8.2 | |
DNN (DotNetNuke) | =4.8.3 | |
DNN (DotNetNuke) | =4.8.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The CVE-2008-7100 vulnerability has a medium severity rating due to its potential for privilege escalation by authenticated users.
To mitigate CVE-2008-7100, upgrade your DotNetNuke installation to version 4.9.0 or later.
CVE-2008-7100 affects DotNetNuke versions from 4.4.1 to 4.8.4 inclusive.
CVE-2008-7100 can be exploited by remote authenticated users who can bypass authentication and gain elevated privileges.
The risks associated with CVE-2008-7100 include unauthorized access and control over the DotNetNuke application for affected users.