Mode:  
News Archive Minimize
Print  
My-ASP.Net

My-ASP.Net News

Keep up to date with the latest News Bulletins and Security Alerts that could affect your website

 

DotNetNuke Multiple Exploits - Low Risk Minimize
Location: BlogsMy-ASP.Net NewsSecurity Alerts    
Posted by: host 6/2/2008 8:49 AM

Description:

A security vulnerability has been found in all DotNetNuke versions including 4.8.3 that can be exploited to allow malicious individuals to casue Denial of Service attacks (DoS) manipulate URLs and bypass DotNetNuke security restricitions.

The Issue(s)

  1. The URL and FileManager API security can be compromised allowing unwanted files to be uploaded to restricted folders
  2. DotNetNuke's install / upgrade process can be exploited allowing a malicious person(s) to send a large number of crafted requests to the DotNetNuke application causing the database to be corrupted or overwritten
  3. Certain input passed via the URL is not properly sanitised before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.

Solution:


Remove all of the *.txt files from the /Portals/_default folder. This will protect your site from being susceptible to automated security scanners or other probing tools typically used by malicious parties.


Update to version 4.8.4. as soon as it is available.

Original Advisory:
http://www.dotnetnuke.com/News/Securi...yBulletinno14/tabid/1159/Default.aspx
http://www.dotnetnuke.com/News/Securi...yBulletinno15/tabid/1160/Default.aspx

Action Request

If you suspect or know that your DotNetNuke Site has been compromised please contact our hostmaster for a free DotnetNuke website security analysis and assistance in preventing further unwanted events.

 

Permalink |  Trackback