DNN (DotNetNuke) < 3.0.12 Multiple XSS

medium Nessus Plugin ID 18505

Synopsis

The remote host contains an ASP application that is affected by multiple input validation flaws.

Description

The remote host is running DNN, a portal written in ASP.

The remote installation of DNN, according to its version number, contains several input validation flaws leading to the execution of attacker supplied HTML and script code.

Solution

Upgrade to DNN version 3.0.12 or later.

See Also

https://seclists.org/bugtraq/2005/May/197

Plugin Details

Severity: Medium

ID: 18505

File Name: dotnetnuke_xss.nasl

Version: 1.26

Type: remote

Published: 6/16/2005

Updated: 6/5/2024

Configuration: Enable thorough checks

Supported Sensors: Nessus

Enable CGI Scanning: true

Risk Information

VPR

Risk Factor: Low

Score: 3.0

CVSS v2

Risk Factor: Medium

Base Score: 4.3

Temporal Score: 3.7

Vector: CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Information

CPE: cpe:/a:dotnetnuke:dotnetnuke

Required KB Items: installed_sw/DNN

Excluded KB Items: Settings/disable_cgi_scanning

Exploit Ease: No exploit is required

Vulnerability Publication Date: 5/16/2005

Reference Information

CVE: CVE-2005-0040

BID: 13644, 13646, 13647

CWE: 20, 442, 629, 711, 712, 722, 725, 74, 750, 751, 79, 800, 801, 809, 811, 864, 900, 928, 931, 990