The installation wizard in DotNetNuke (DNN) before 7.4.1 allows remote attackers to reinstall the application and gain SuperUser access via a direct request to Install/InstallWizard.aspx.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Dotnetnuke |
Dotnetnuke |
* |
07.04.00 (including) |
References