5.1
CVSSv2

CVE-2008-6540

Published: 30/03/2009 Updated: 11/10/2018
CVSS v2 Base Score: 5.1 | Impact Score: 6.4 | Exploitability Score: 4.9
VMScore: 515
Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P

Vulnerability Summary

DotNetNuke prior to 4.8.2, during installation or upgrade, does not warn the administrator when the default (1) ValidationKey and (2) DecryptionKey values cannot be modified in the web.config file, which allows remote malicious users to bypass intended access restrictions by using the default keys.

Vulnerable Product Search on Vulmon Subscribe to Product

dotnetnuke dotnetnuke 4.0

dotnetnuke dotnetnuke 3.0.11

dotnetnuke dotnetnuke 1.0.10e

dotnetnuke dotnetnuke 1.0.10d

dotnetnuke dotnetnuke 2.1.2

dotnetnuke dotnetnuke 2.1.1

dotnetnuke dotnetnuke 4.3.5

dotnetnuke dotnetnuke 3.3.5

dotnetnuke dotnetnuke 1.0.9

dotnetnuke dotnetnuke 1.0.8

dotnetnuke dotnetnuke 4.5.2

dotnetnuke dotnetnuke

dotnetnuke dotnetnuke 3.0.7

dotnetnuke dotnetnuke 3.0.8

dotnetnuke dotnetnuke 3.1.0

dotnetnuke dotnetnuke 1.0.7

dotnetnuke dotnetnuke 1.0.6

Exploits

source: wwwsecurityfocuscom/bid/28391/info DotNetNuke is prone to a weak encryption vulnerability An attacker can exploit this issue to decrypt sensitive data Information obtained may lead to further attacks This issue affects DotNetNuke 481; other versions may also be affected // Step 1: Generate the two FormsAuthenticationTi ...