Cross-site scripting (XSS) vulnerability in Default.aspx in Perpetual Motion Interactive Systems DotNetNuke before 3.3.5, and 4.x before 4.3.5, allows remote attackers to inject arbitrary HTML via the error parameter.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Dotnetnuke | Dotnetnuke | 1.0.6 (including) | 1.0.6 (including) |
Dotnetnuke | Dotnetnuke | 1.0.7 (including) | 1.0.7 (including) |
Dotnetnuke | Dotnetnuke | 1.0.8 (including) | 1.0.8 (including) |
Dotnetnuke | Dotnetnuke | 1.0.9 (including) | 1.0.9 (including) |
Dotnetnuke | Dotnetnuke | 1.0.10d (including) | 1.0.10d (including) |
Dotnetnuke | Dotnetnuke | 1.0.10e (including) | 1.0.10e (including) |
Dotnetnuke | Dotnetnuke | 2.1.1 (including) | 2.1.1 (including) |
Dotnetnuke | Dotnetnuke | 2.1.2 (including) | 2.1.2 (including) |
Dotnetnuke | Dotnetnuke | 3.0.7 (including) | 3.0.7 (including) |
Dotnetnuke | Dotnetnuke | 3.0.8 (including) | 3.0.8 (including) |
Dotnetnuke | Dotnetnuke | 3.1.0 (including) | 3.1.0 (including) |
Dotnetnuke | Dotnetnuke | 4.0 (including) | 4.0 (including) |