First published: Sat Nov 28 2009(Updated: )
Cross-site scripting (XSS) vulnerability in the search functionality in DotNetNuke 4.8 through 5.1.4 allows remote attackers to inject arbitrary web script or HTML via search terms that are not properly filtered before display in a custom results page.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
DNN (DotNetNuke) | =4.8.0 | |
DNN (DotNetNuke) | =4.8.1 | |
DNN (DotNetNuke) | =4.8.2 | |
DNN (DotNetNuke) | =4.8.3 | |
DNN (DotNetNuke) | =4.8.4 | |
DNN (DotNetNuke) | =4.9 | |
DNN (DotNetNuke) | =4.9.1 | |
DNN (DotNetNuke) | =4.9.2 | |
DNN (DotNetNuke) | =5.0 | |
DNN (DotNetNuke) | =5.1 | |
DNN (DotNetNuke) | =5.1.1 | |
DNN (DotNetNuke) | =5.1.2 | |
DNN (DotNetNuke) | =5.1.3 | |
DNN (DotNetNuke) | =5.1.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-4110 is classified as a medium severity vulnerability due to its potential for exploitation through cross-site scripting.
To fix CVE-2009-4110, upgrade DotNetNuke to version 5.1.5 or later, where the vulnerability has been patched.
CVE-2009-4110 affects DotNetNuke versions 4.8 through 5.1.4.
The impact of CVE-2009-4110 allows remote attackers to execute arbitrary web scripts or HTML through crafted search terms.
CVE-2009-4110 is a known and documented vulnerability, making it important for users of affected DotNetNuke versions to address it promptly.