356
VMScore

CVE-2020-5188

Published: 24/02/2020 Updated: 07/11/2023
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:N/I:P/A:N

Vulnerability Summary

DNN (formerly DotNetNuke) up to and including 9.4.4 has Insecure Permissions.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

dnnsoftware dotnetnuke

Exploits

DotNetNuke CMS version 944 suffers from zip split issue where a directory traversal attack can be performed to overwrite files or execute malicious code ...
DotNetNuke CMS version 950 suffers from file extension check bypass vulnerability that allows for arbitrary file upload ...