CVE-2009-1366
Dotnetnuke < 4.9.2 - XSS
Title source: ruleDescription
Cross-site scripting (XSS) vulnerability in Website\admin\Sales\paypalipn.aspx in DotNetNuke (DNN) before 4.9.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to "name/value pairs" and "paypal IPN functionality."
Scores
EPSS
0.0032
EPSS Percentile
54.9%
Classification
CWE
CWE-79
Status
published
Affected Products (31)
dotnetnuke/dotnetnuke
< 4.9.2
dotnetnuke/dotnetnuke
dotnetnuke/dotnetnuke
dotnetnuke/dotnetnuke
dotnetnuke/dotnetnuke
dotnetnuke/dotnetnuke
dotnetnuke/dotnetnuke
dotnetnuke/dotnetnuke
dotnetnuke/dotnetnuke
dotnetnuke/dotnetnuke
dotnetnuke/dotnetnuke
dotnetnuke/dotnetnuke
dotnetnuke/dotnetnuke
dotnetnuke/dotnetnuke
dotnetnuke/dotnetnuke
... and 16 more
Timeline
Published
Apr 22, 2009
Tracked Since
Feb 18, 2026