VulnerabilityModified
CVE-2009-4109
The install wizard in DotNetNuke 4.0 through 5.1.4 does not prevent anonymous users from accessing functionality related to determination of the need for an upgrade, which allows remote attackers to access version information and possibly other…
MEDIUM 5.0EPSS 1.23%
Does this matter?
Lower severity and a low EPSS score (1.23%). Track it; it rarely justifies an emergency change on its own.
Description
The install wizard in DotNetNuke 4.0 through 5.1.4 does not prevent anonymous users from accessing functionality related to determination of the need for an upgrade, which allows remote attackers to access version information and possibly other sensitive information.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 1.23% probability · 67th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- dnnsoftware/dotnetnuke
- Source
- cve@mitre.org
References
- http://osvdb.org/60520
- http://secunia.com/advisories/37480Vendor Advisory
- http://www.dotnetnuke.com/News/SecurityPolicy/securitybulletinno30/tabid/1449/Default.aspxVendor Advisory
- http://www.securityfocus.com/bid/37139
- http://osvdb.org/60520
- http://secunia.com/advisories/37480Vendor Advisory
- http://www.dotnetnuke.com/News/SecurityPolicy/securitybulletinno30/tabid/1449/Default.aspxVendor Advisory
- http://www.securityfocus.com/bid/37139
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.