Vulnerabilities > Dotnetnuke > Dotnetnuke > 07.03.04
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2017-02-06 | CVE-2015-2794 | Permissions, Privileges, and Access Controls vulnerability in Dotnetnuke The installation wizard in DotNetNuke (DNN) before 7.4.1 allows remote attackers to reinstall the application and gain SuperUser access via a direct request to Install/InstallWizard.aspx. | 7.5 |
2016-08-31 | CVE-2016-7119 | Cross-site Scripting vulnerability in Dotnetnuke Cross-site scripting (XSS) vulnerability in the user-profile biography section in DotNetNuke (DNN) before 8.0.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted onclick attribute in an IMG element. | 3.5 |
2015-02-09 | CVE-2015-1566 | Cross-site Scripting vulnerability in Dotnetnuke Cross-site scripting (XSS) vulnerability in DotNetNuke (DNN) before 7.4.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | 4.3 |