Lucene search

K
cve[email protected]CVE-2008-6542
HistoryMar 30, 2009 - 1:30 a.m.

CVE-2008-6542

2009-03-3001:30:00
web.nvd.nist.gov
23
cve-2008-6542
dotnetnuke
skin manager
remote code execution
htm
html
nvd

4.6 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:H/Au:S/C:P/I:P/A:P

6.3 Medium

AI Score

Confidence

Low

0.006 Low

EPSS

Percentile

77.8%

Unspecified vulnerability in the Skin Manager in DotNetNuke before 4.8.2 allows remote authenticated administrators to perform “server-side execution of application logic” by uploading a static file that is converted into a dynamic script via unknown vectors related to HTM or HTML files.

Affected configurations

NVD
Node
dotnetnukedotnetnukeRange4.8.1
OR
dotnetnukedotnetnukeMatch1.0.6
OR
dotnetnukedotnetnukeMatch1.0.7
OR
dotnetnukedotnetnukeMatch1.0.8
OR
dotnetnukedotnetnukeMatch1.0.9
OR
dotnetnukedotnetnukeMatch1.0.10d
OR
dotnetnukedotnetnukeMatch1.0.10e
OR
dotnetnukedotnetnukeMatch2.1.1
OR
dotnetnukedotnetnukeMatch2.1.2
OR
dotnetnukedotnetnukeMatch3.0.7
OR
dotnetnukedotnetnukeMatch3.0.8
OR
dotnetnukedotnetnukeMatch3.0.11
OR
dotnetnukedotnetnukeMatch3.1.0
OR
dotnetnukedotnetnukeMatch4.0
OR
dotnetnukedotnetnukeMatch4.5.2

4.6 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:H/Au:S/C:P/I:P/A:P

6.3 Medium

AI Score

Confidence

Low

0.006 Low

EPSS

Percentile

77.8%

Related for CVE-2008-6542