96306vdb entry
http://osvdb.org/96306 CVE-2013-5117
DotNetNuke DNNArticle Module 10.0 - SQL Injection
Record summary
CVE-2013-5117 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.
Description
SQL injection vulnerability in the RSS page (DNNArticleRSS.aspx) in the ZLDNN DNNArticle module before 10.1 for DotNetNuke allows remote attackers to execute arbitrary SQL commands via the categoryid parameter.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBDotNetNuke DNNArticle Module 10.0 - SQL InjectionExploitDB exploitby Sajjad PouraliNot analyzed1 file
References
620130902 DotNetNuke (DNNArticle Module) SQL Injection Vulnerabilitymailing list
http://seclists.org/fulldisclosure/2013/Sep/9 27602exploit
http://www.exploit-db.com/exploits/27602 61788vdb entry
http://www.securityfocus.com/bid/61788 zldnn.comConfirmation
http://www.zldnn.com/ViewArticle/Solution-for-DNNArticle-RSS-Security-Issue.aspx nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2013-5117