Lucene search

K
cveMitreCVE-2009-4109
HistoryNov 29, 2009 - 1:08 p.m.

CVE-2009-4109

2009-11-2913:08:29
CWE-200
mitre
web.nvd.nist.gov
32
dotnetnuke
install wizard
unauthorized access
cve-2009-4109
information security

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

6.5

Confidence

Low

EPSS

0.004

Percentile

72.4%

The install wizard in DotNetNuke 4.0 through 5.1.4 does not prevent anonymous users from accessing functionality related to determination of the need for an upgrade, which allows remote attackers to access version information and possibly other sensitive information.

Affected configurations

Nvd
Node
dotnetnukedotnetnukeMatch4.0
OR
dotnetnukedotnetnukeMatch4.3.5
OR
dotnetnukedotnetnukeMatch4.4.1
OR
dotnetnukedotnetnukeMatch4.5.2
OR
dotnetnukedotnetnukeMatch4.5.4
OR
dotnetnukedotnetnukeMatch4.5.5
OR
dotnetnukedotnetnukeMatch4.6.0
OR
dotnetnukedotnetnukeMatch4.6.1
OR
dotnetnukedotnetnukeMatch4.6.2
OR
dotnetnukedotnetnukeMatch4.7.0
OR
dotnetnukedotnetnukeMatch4.8.0
OR
dotnetnukedotnetnukeMatch4.8.1
OR
dotnetnukedotnetnukeMatch4.8.2
OR
dotnetnukedotnetnukeMatch4.8.3
OR
dotnetnukedotnetnukeMatch4.8.4
OR
dotnetnukedotnetnukeMatch4.9
OR
dotnetnukedotnetnukeMatch4.9.1
OR
dotnetnukedotnetnukeMatch4.9.2
OR
dotnetnukedotnetnukeMatch5.0
OR
dotnetnukedotnetnukeMatch5.1
OR
dotnetnukedotnetnukeMatch5.1.1
OR
dotnetnukedotnetnukeMatch5.1.2
OR
dotnetnukedotnetnukeMatch5.1.3
OR
dotnetnukedotnetnukeMatch5.1.4
VendorProductVersionCPE
dotnetnukedotnetnuke4.0cpe:2.3:a:dotnetnuke:dotnetnuke:4.0:*:*:*:*:*:*:*
dotnetnukedotnetnuke4.3.5cpe:2.3:a:dotnetnuke:dotnetnuke:4.3.5:*:*:*:*:*:*:*
dotnetnukedotnetnuke4.4.1cpe:2.3:a:dotnetnuke:dotnetnuke:4.4.1:*:*:*:*:*:*:*
dotnetnukedotnetnuke4.5.2cpe:2.3:a:dotnetnuke:dotnetnuke:4.5.2:*:*:*:*:*:*:*
dotnetnukedotnetnuke4.5.4cpe:2.3:a:dotnetnuke:dotnetnuke:4.5.4:*:*:*:*:*:*:*
dotnetnukedotnetnuke4.5.5cpe:2.3:a:dotnetnuke:dotnetnuke:4.5.5:*:*:*:*:*:*:*
dotnetnukedotnetnuke4.6.0cpe:2.3:a:dotnetnuke:dotnetnuke:4.6.0:*:*:*:*:*:*:*
dotnetnukedotnetnuke4.6.1cpe:2.3:a:dotnetnuke:dotnetnuke:4.6.1:*:*:*:*:*:*:*
dotnetnukedotnetnuke4.6.2cpe:2.3:a:dotnetnuke:dotnetnuke:4.6.2:*:*:*:*:*:*:*
dotnetnukedotnetnuke4.7.0cpe:2.3:a:dotnetnuke:dotnetnuke:4.7.0:*:*:*:*:*:*:*
Rows per page:
1-10 of 241

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

6.5

Confidence

Low

EPSS

0.004

Percentile

72.4%

Related for CVE-2009-4109