SB2015052801 - Improper access control in DotNetNuke
Published: May 28, 2015
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper access control (CVE-ID: CVE-2015-2794)
The vulnerability allows a remote attacker to gain complete control over vulnerable web application.
The vulnerability exists due to improper access control to DotnetNuke installation script /Install/InstallWizard.aspx. A remote unauthenticated attacker can guess SQL Server instance name and reinstall DotnetNuke application.
Successful exploitation of the vulnerability will allow an attacker to gain complete access to the web application.
Remediation
Install update from vendor's website.