DNN (formerly DotNetNuke) through 9.4.4 has Insecure Permissions.
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Link | Tags |
---|---|
https://github.com/dnnsoftware/Dnn.Platform/releases | third party advisory release notes |
http://packetstormsecurity.com/files/156484/DotNetNuke-CMS-9.5.0-File-Extension-Check-Bypass.html | exploit vdb entry third party advisory |
https://medium.com/%40SajjadPourali/dnn-dotnetnuke-cms-not-as-secure-as-you-think-e8516f789175 |