vendor:
DNNArticle
by:
Esmaeil Rahimian
9.8
CVSS
CRITICAL
Directory Traversal
22
CWE
Product Name: DNNArticle
Affected Version From: 11
Affected Version To: 11
Patch Exists: YES
Related CWE: CVE-2018-9126
CPE: a:zldnn.com:dnnarticle:11
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: None
2018
Directory Traversal Vulnerability in DNNarticle module
The DNNArticle module 11 for DNN (formerly DotNetNuke) allows remote attackers to read the web.config file, and consequently discover database credentials, via the /GetCSS.ashx/?CP=%2fweb.config URI.
Mitigation:
Upgrade to DNNArticle 11.1.1 or later.