漏洞描述 DotNetNuke(DNN)是美国DNN公司的一套由微软支持、基于ASP.NET平台的开源内容管理系统(CMS)。该系统具有易于安装、可扩展、功能丰富等特点。DNN 7.4.1之前的版本中的installationwizard存在安全漏洞。远程攻击者可通过向Install/InstallWizard.aspx文件发送直接请求利用该漏洞重新安装应用程序,并获取SuperUser访问权限
相关漏洞推荐 CVE-2025-52488: DNN (DotNetNuke) - Unicode Path Normalization NTLM Hash Disclosure POC 2025-09-01 | DNN DotNetNuke DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft e... CVE-2015-2794: DotNetNuke 07.04.00 - Administration Authentication Bypass POC 2025-08-01 | DotNetNuke The installation wizard in DotNetNuke (DNN) before 7.4.1 allows remote attackers to reinstall the ap... CVE-2017-0929: DotNetNuke (DNN) ImageHandler <9.2.0 - Server-Side Request Forgery POC 2025-08-01 | DotNetNuke DotNetNuke (aka DNN) before 9.2.0 suffers from a server-side request forgery vulnerability in the Dn... CVE-2015-1427: ElasticSearch - Remote Code Execution POC 2025-09-01 | ElasticSearch ElasticSearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the sandbox prot... CVE-2015-3337: Elasticsearch CVE-2015-3337 POC 2025-09-01 | Elasticsearch fofa app="elastic-Elasticsearch"