5
CVSSv2

CVE-2004-2323

Published: 31/12/2004 Updated: 11/07/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

DotNetNuke (formerly IBuySpy Workshop) 1.0.6 up to and including 1.0.10d allows remote malicious users to obtain sensitive information, including the SQL server username and password, via a GET request for source or configuration files such as Web.config.

Vulnerable Product Search on Vulmon Subscribe to Product

dotnetnuke dotnetnuke 1.0.10d

dotnetnuke dotnetnuke 1.0.8

dotnetnuke dotnetnuke 1.0.9

dotnetnuke dotnetnuke 1.0.6

dotnetnuke dotnetnuke 1.0.7