CVE-2009-4110: XSS
Cross-site scripting (XSS) vulnerability in the search functionality in DotNetNuke 4.8 through 5.1.4 allows remote attackers to inject arbitrary web script or HTML via search terms that are not properly filtered before display in a custom results page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-4110?
CVE-2009-4110 is classified as a medium severity vulnerability due to its potential for exploitation through cross-site scripting.
How do I fix CVE-2009-4110?
To fix CVE-2009-4110, upgrade DotNetNuke to version 5.1.5 or later, where the vulnerability has been patched.
What versions of DotNetNuke are affected by CVE-2009-4110?
CVE-2009-4110 affects DotNetNuke versions 4.8 through 5.1.4.
What is the impact of CVE-2009-4110?
The impact of CVE-2009-4110 allows remote attackers to execute arbitrary web scripts or HTML through crafted search terms.
Is CVE-2009-4110 a common vulnerability?
CVE-2009-4110 is a known and documented vulnerability, making it important for users of affected DotNetNuke versions to address it promptly.