CVE Vulnerabilities

CVE-2006-4973

Published: Sep 25, 2006 | Modified: Jul 20, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

Cross-site scripting (XSS) vulnerability in Default.aspx in Perpetual Motion Interactive Systems DotNetNuke before 3.3.5, and 4.x before 4.3.5, allows remote attackers to inject arbitrary HTML via the error parameter.

Affected Software

Name Vendor Start Version End Version
Dotnetnuke Dotnetnuke 2.1.1 2.1.1
Dotnetnuke Dotnetnuke 1.0.10e 1.0.10e
Dotnetnuke Dotnetnuke 1.0.10d 1.0.10d
Dotnetnuke Dotnetnuke 1.0.7 1.0.7
Dotnetnuke Dotnetnuke 1.0.8 1.0.8
Dotnetnuke Dotnetnuke 1.0.6 1.0.6
Dotnetnuke Dotnetnuke 1.0.9 1.0.9
Dotnetnuke Dotnetnuke 3.0.8 3.0.8
Dotnetnuke Dotnetnuke 2.1.2 2.1.2
Dotnetnuke Dotnetnuke 4.0 4.0
Dotnetnuke Dotnetnuke 3.0.7 3.0.7
Dotnetnuke Dotnetnuke 3.1.0 3.1.0

References