DotNetNuke before 4.8.2, during installation or upgrade, does not warn the administrator when the default (1) ValidationKey and (2) DecryptionKey values cannot be modified in the web.config file, which allows remote attackers to bypass intended access restrictions by using the default keys.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/41399 | vdb entry |
http://www.dotnetnuke.com/News/SecurityBulletins/SecurityBulletinno12/tabid/1148/Default.aspx | vendor advisory |
http://www.securityfocus.com/bid/28391 | vdb entry exploit |
http://secunia.com/advisories/29488 | third party advisory vendor advisory |
http://www.securityfocus.com/archive/1/489957/100/0/threaded | mailing list |
http://osvdb.org/43720 | vdb entry |