Количество 2
Количество 2
CVE-2008-6540
DotNetNuke before 4.8.2, during installation or upgrade, does not warn the administrator when the default (1) ValidationKey and (2) DecryptionKey values cannot be modified in the web.config file, which allows remote attackers to bypass intended access restrictions by using the default keys.
GHSA-grw3-hjjm-5cjm
DotNetNuke Default Machine Key Exposure
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2008-6540 DotNetNuke before 4.8.2, during installation or upgrade, does not warn the administrator when the default (1) ValidationKey and (2) DecryptionKey values cannot be modified in the web.config file, which allows remote attackers to bypass intended access restrictions by using the default keys. | CVSS2: 5.1 | 5% Низкий | почти 17 лет назад | |
GHSA-grw3-hjjm-5cjm DotNetNuke Default Machine Key Exposure | 5% Низкий | больше 3 лет назад |
Уязвимостей на страницу