CVE-2008-6540
23Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 2.5%
from disclosure to weapon0 days
Published on NVDMar 30
1st PoCMar 21
exploitation probability
2.5%top 17% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
DotNetNuke before 4.8.2, during installation or upgrade, does not warn the administrator when the default (1) ValidationKey and (2) DecryptionKey values cannot be modified in the web.config file, which allows remote attackers to bypass intended access restrictions by using the default keys.
Affected products
n/a · n/apublic PoCs found — 1✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/31465⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://osvdb.org/43720http://secunia.com/advisories/29488https://exchange.xforce.ibmcloud.com/vulnerabilities/41399http://www.dotnetnuke.com/News/SecurityBulletins/SecurityBulletinno12/tabid/1148/Default.aspxhttp://www.securityfocus.com/archive/1/489957/100/0/threadedhttp://www.securityfocus.com/bid/28391