CVE Database
/

CVE-2009-4109

Back to search

CVE-2009-4109

Published: Nov 28, 2009

Modified: Sep 16, 2024

PUBLISHED

Description

The install wizard in DotNetNuke 4.0 through 5.1.4 does not prevent anonymous users from accessing functionality related to determination of the need for an upgrade, which allows remote attackers to access version information and possibly other sensitive information.

VendorProductVersions

n/a

n/a

affected
n/a

References

37480
third-party-advisory
x_refsource_SECUNIA
37139
vdb-entry
x_refsource_BID
60520
vdb-entry
x_refsource_OSVDB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now