CVE-2010-4514: XSS
Published Dec 9, 2010
·Updated
Cross-site scripting (XSS) vulnerability in Install/InstallWizard.aspx in DotNetNuke 5.05.01 and 5.06.00 allows remote attackers to inject arbitrary web script or HTML via the VIEWSTATE parameter. NOTE: some of these details are obtained from third party information.
Affected Software
4 affected components
DotNetNuke DotNetNuke=5.05.01
DotNetNuke DotNetNuke=5.06.00
dnnsoftware Dotnetnuke=5.05.01
dnnsoftware Dotnetnuke=5.06.00
Event History
Dec 9, 2010
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Data Sourced
via NVD·09:00 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2010-4514?
CVE-2010-4514 has a medium severity rating due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2010-4514?
To fix CVE-2010-4514, upgrade DotNetNuke to version 5.06.01 or later.
3
What is the vulnerability type of CVE-2010-4514?
CVE-2010-4514 is classified as a cross-site scripting (XSS) vulnerability.
4
Which versions of DotNetNuke are affected by CVE-2010-4514?
CVE-2010-4514 affects DotNetNuke versions 5.05.01 and 5.06.00.
5
Can CVE-2010-4514 allow remote attacks?
Yes, CVE-2010-4514 allows remote attackers to inject arbitrary web script or HTML.