Vulnerability Details CVE-2008-6540
DotNetNuke before 4.8.2, during installation or upgrade, does not warn the administrator when the default (1) ValidationKey and (2) DecryptionKey values cannot be modified in the web.config file, which allows remote attackers to bypass intended access restrictions by using the default keys.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.076
EPSS Ranking 92.0%
CVSS Severity
CVSS v2 Score 5.1
Products affected by CVE-2008-6540
-
cpe:2.3:a:dnnsoftware:dotnetnuke:1.0.10d
-
cpe:2.3:a:dnnsoftware:dotnetnuke:1.0.10e
-
cpe:2.3:a:dnnsoftware:dotnetnuke:1.0.6
-
cpe:2.3:a:dnnsoftware:dotnetnuke:1.0.7
-
cpe:2.3:a:dnnsoftware:dotnetnuke:1.0.8
-
cpe:2.3:a:dnnsoftware:dotnetnuke:1.0.9
-
cpe:2.3:a:dnnsoftware:dotnetnuke:2.1.1
-
cpe:2.3:a:dnnsoftware:dotnetnuke:2.1.2
-
cpe:2.3:a:dnnsoftware:dotnetnuke:3.0.11
-
cpe:2.3:a:dnnsoftware:dotnetnuke:3.0.7
-
cpe:2.3:a:dnnsoftware:dotnetnuke:3.0.8
-
cpe:2.3:a:dnnsoftware:dotnetnuke:3.1.0
-
cpe:2.3:a:dnnsoftware:dotnetnuke:3.3.5
-
cpe:2.3:a:dnnsoftware:dotnetnuke:4.0
-
cpe:2.3:a:dnnsoftware:dotnetnuke:4.3.5
-
cpe:2.3:a:dnnsoftware:dotnetnuke:4.4.1
-
cpe:2.3:a:dnnsoftware:dotnetnuke:4.5.2
-
cpe:2.3:a:dnnsoftware:dotnetnuke:4.5.4
-
cpe:2.3:a:dnnsoftware:dotnetnuke:4.5.5
-
cpe:2.3:a:dnnsoftware:dotnetnuke:4.6.0
-
cpe:2.3:a:dnnsoftware:dotnetnuke:4.6.1
-
cpe:2.3:a:dnnsoftware:dotnetnuke:4.6.2
-
cpe:2.3:a:dnnsoftware:dotnetnuke:4.7.0
-
cpe:2.3:a:dnnsoftware:dotnetnuke:4.8.0
-
cpe:2.3:a:dnnsoftware:dotnetnuke:4.8.1