CVE-2018-9126 Information
Feb 14, 2021
cve
Description
The DNNArticle module 11 for DNN (formerly DotNetNuke) allows remote attackers to read the web.config file and consequently discover database credentials via the /GetCSS.ashx/?CP=2fweb.config URI.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Reference
http://packetstormsecurity.com/files/146999/DotNetNuke-DNNarticle-Directory-Traversal.html https://www.exploit-db.com/exploits/44414/
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
9.8
Share on: