Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2017-0929 PoC — DNN 安全漏洞

Source
Associated Vulnerability
Title:DNN 安全漏洞 (CVE-2017-0929)
Description:DNN(前称DotNetNuke)是美国DNN公司的一套由微软支持、基于ASP.NET平台的开源内容管理系统(CMS)。该系统具有易于安装、可扩展、功能丰富等特点。 DNN 9.2.0之前版本中的DnnImageHandler类存在服务器端请求伪造漏洞。远程攻击者可利用该漏洞访问有关内部网络资源的信息。
Description
DotNetNuke (aka DNN) before 9.2.0 suffers from a server-side request forgery vulnerability in the DnnImageHandler class. Attackers may be able to access information about internal network resources.
File Snapshot

id: CVE-2017-0929 info: name: DotNetNuke (DNN) ImageHandler <9.2.0 - Server-Side Request Forgery ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.