Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The install wizard in DotNetNuke 4.0 through 5.1.4 does not prevent anonymous users from accessing functionality related to determination of the need for an upgrade, which allows remote attackers to access version information and possibly other sensitive information.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
DotNetNuke 安装向导跨站脚本攻击和信息泄露漏洞
Vulnerability Description
DotNetNuke 4.0版本至5.1.4版本的安装wizard没有阻止匿名用户访问有关升级的功能,这会允许远程攻击者访问版本信息和其他可能的敏感信息。
CVSS Information
N/A
Vulnerability Type
N/A