Vulnerabilities > CVE-2008-6542 - Remote vulnerability in DotNetNuke Prior to 4.8.2
Summary
Unspecified vulnerability in the Skin Manager in DotNetNuke before 4.8.2 allows remote authenticated administrators to perform "server-side execution of application logic" by uploading a static file that is converted into a dynamic script via unknown vectors related to HTM or HTML files. Per vendor advisory: http://www.dotnetnuke.com/News/SecurityBulletins/SecurityBulletinno13/tabid/1149/Default.aspx Mitigating factors * The host user must have added the HTM or HTML file type to the default File Upload Extensions * The user must have access to the file manager. * By default this issue only affects Admin users.