Record summary

CVE-2017-0929 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.

Description

DNN (aka DotNetNuke) before 9.2.0 suffers from a Server-Side Request Forgery (SSRF) vulnerability in the DnnImageHandler class. Attackers may be able to access information about internal network resources.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Sep 19, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

Affected products and versions

2
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied
GitHub AdvisoryBefore 9.2.0 · Fixed in 9.2.0affected

Nuclei templates

1
ProjectDiscoveryHIGHDotNetNuke (DNN) ImageHandler <9.2.0 - Server-Side Request ForgeryCVSS 7.5

DotNetNuke (aka DNN) before 9.2.0 suffers from a server-side request forgery vulnerability in the DnnImageHandler class. Attackers may be able to access information about internal network resources.

Impact

An attacker can exploit this vulnerability to bypass security controls, access internal resources, and potentially perform further attacks.

Remediation

Upgrade DotNetNuke (DNN) ImageHandler to version 9.2.0 or above.

WeaknessesCWE-918
Authorscharanrayudu, meme-lord
Template tagscve2017cvednndotnetnukehackeroneoastssrfdnnsoftwarevkevvuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:dnnsoftware:dotnetnuke:*:*:*:*:*:*:*:*
FOFA: app="dotnetnuke"

Source: ProjectDiscovery

References

4