vendor:
DotNetNuke
by:
Marios Nicolaides
9.8
CVSS
CRITICAL
Authentication Bypass
Unknown
CWE
Product Name: DotNetNuke
Affected Version From: 07.04.00
Affected Version To: 07.04.00
Patch Exists: NO
Related CWE: CVE-2015-2794
CPE: Unknown
Platforms Tested: Windows 7 Professional (64-bit)
2016
DotNetNuke 07.04.00 Administration Authentication Bypass
DotNetNuke 07.04.00 does not prevent anonymous users from accessing the installation wizard, allowing a remote attacker to 'reinstall' DNN and gain unauthorized access as a SuperUser. Previous versions of DotNetNuke may also be affected.
Mitigation:
Unknown