DotNetNuke (aka DNN) before 9.2.0 suffers from a server-side request forgery vulnerability in the DnnImageHandler class. Attackers may be able to access information about internal network resources.
id: CVE-2017-0929
info:
name: DotNetNuke (DNN) ImageHandler <9.2.0 - Server-Side Request Forgery
...