Vulnerabilities > Dotnetnuke > Medium

DATE CVE VULNERABILITY TITLE RISK
2004-12-31 CVE-2004-2325 Multiple vulnerability in DotNetNuke
Cross-site scripting (XSS) vulnerability in EditModule.aspx for DotNetNuke (formerly IBuySpy Workshop) 1.0.6 through 1.0.10d allows remote attackers to inject arbitrary web script or HTML.
network
dotnetnuke
4.3
2004-12-31 CVE-2004-2323 Multiple vulnerability in DotNetNuke
DotNetNuke (formerly IBuySpy Workshop) 1.0.6 through 1.0.10d allows remote attackers to obtain sensitive information, including the SQL server username and password, via a GET request for source or configuration files such as Web.config.
network
low complexity
dotnetnuke
5.0