packetstormsecurity.com
http://packetstormsecurity.com/files/146999/DotNetNuke-DNNarticle-Directory-Traversal.html CVE-2018-9126
CRITICAL
DotNetNuke DNNarticle Module 11 - Directory Traversal
Record summary
CVE-2018-9126 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit.
Description
The DNNArticle module 11 for DNN (formerly DotNetNuke) allows remote attackers to read the web.config file, and consequently discover database credentials, via the /GetCSS.ashx/?CP=%2fweb.config URI.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBDotNetNuke DNNarticle Module 11 - Directory TraversalExploitDB exploitby Esmaeil RahimianNot analyzed1 file
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2018-9126 44414exploit
https://www.exploit-db.com/exploits/44414