SB2015052801 - Improper access control in DotNetNuke



SB2015052801 - Improper access control in DotNetNuke

Published: May 28, 2015

Security Bulletin ID SB2015052801
Severity
High
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Improper access control (CVE-ID: CVE-2015-2794)

The vulnerability allows a remote attacker to gain complete control over vulnerable web application.

The vulnerability exists due to improper access control to DotnetNuke installation script /Install/InstallWizard.aspx. A remote unauthenticated attacker can guess SQL Server instance name and reinstall DotnetNuke application.

Successful exploitation of the vulnerability will allow an attacker to gain complete access to the web application.


Remediation

Install update from vendor's website.