CVE Vulnerabilities

CVE-2006-4973

Published: Sep 25, 2006 | Modified: Apr 24, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Cross-site scripting (XSS) vulnerability in Default.aspx in Perpetual Motion Interactive Systems DotNetNuke before 3.3.5, and 4.x before 4.3.5, allows remote attackers to inject arbitrary HTML via the error parameter.

Affected Software

NameVendorStart VersionEnd Version
DotnetnukeDnnsoftware1.0.6 (including)1.0.6 (including)
DotnetnukeDnnsoftware1.0.7 (including)1.0.7 (including)
DotnetnukeDnnsoftware1.0.8 (including)1.0.8 (including)
DotnetnukeDnnsoftware1.0.9 (including)1.0.9 (including)
DotnetnukeDnnsoftware1.0.10d (including)1.0.10d (including)
DotnetnukeDnnsoftware1.0.10e (including)1.0.10e (including)
DotnetnukeDnnsoftware2.1.1 (including)2.1.1 (including)
DotnetnukeDnnsoftware2.1.2 (including)2.1.2 (including)
DotnetnukeDnnsoftware3.0.7 (including)3.0.7 (including)
DotnetnukeDnnsoftware3.0.8 (including)3.0.8 (including)
DotnetnukeDnnsoftware3.1.0 (including)3.1.0 (including)
DotnetnukeDnnsoftware4.0 (including)4.0 (including)

References