CVE-2017-9822

DNN (aka DotNetNuke) before 9.1.1 has Remote Code Execution via a cookie, aka "2017-08 (Critical) Possible remote code execution on DNN sites."
Configurations

Configuration 1 (hide)

cpe:2.3:a:dnnsoftware:dotnetnuke:*:*:*:*:*:*:*:*

History

24 Jul 2024, 17:11

Type Values Removed Values Added
CWE CWE-20 NVD-CWE-noinfo
References () http://packetstormsecurity.com/files/157080/DotNetNuke-Cookie-Deserialization-Remote-Code-Execution.html - () http://packetstormsecurity.com/files/157080/DotNetNuke-Cookie-Deserialization-Remote-Code-Execution.html - Exploit, Third Party Advisory, VDB Entry
References () http://www.dnnsoftware.com/community/security/security-center - Vendor Advisory () http://www.dnnsoftware.com/community/security/security-center - Product, Vendor Advisory
References () http://www.securityfocus.com/bid/102213 - Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/102213 - Broken Link, Third Party Advisory, VDB Entry

Information

Published : 2017-07-20 12:29

Updated : 2024-07-24 17:11


NVD link : CVE-2017-9822

Mitre link : CVE-2017-9822

CVE.ORG link : CVE-2017-9822


JSON object : View

Products Affected

dnnsoftware

  • dotnetnuke