CVE-2004-2324

SQL injection vulnerability in DotNetNuke (formerly IBuySpy Workshop) 1.0.6 through 1.0.10d allows remote attackers to modify the backend database via the (1) table and (2) field parameters in LinkClick.aspx.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:dotnetnuke:dotnetnuke:1.0.6:*:*:*:*:*:*:*
cpe:2.3:a:dotnetnuke:dotnetnuke:1.0.7:*:*:*:*:*:*:*
cpe:2.3:a:dotnetnuke:dotnetnuke:1.0.8:*:*:*:*:*:*:*
cpe:2.3:a:dotnetnuke:dotnetnuke:1.0.9:*:*:*:*:*:*:*
cpe:2.3:a:dotnetnuke:dotnetnuke:1.0.10d:*:*:*:*:*:*:*

History

20 Nov 2024, 23:53

Type Values Removed Values Added
References () http://archives.neohapsis.com/archives/fulldisclosure/2004-01/1161.html - Patch, Vendor Advisory () http://archives.neohapsis.com/archives/fulldisclosure/2004-01/1161.html - Patch, Vendor Advisory
References () http://secunia.com/advisories/10747 - () http://secunia.com/advisories/10747 -
References () http://www.osvdb.org/3750 - () http://www.osvdb.org/3750 -
References () http://www.securityfocus.com/bid/9518 - Patch () http://www.securityfocus.com/bid/9518 - Patch
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/14973 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/14973 -

Information

Published : 2004-12-31 05:00

Updated : 2024-11-20 23:53


NVD link : CVE-2004-2324

Mitre link : CVE-2004-2324

CVE.ORG link : CVE-2004-2324


JSON object : View

Products Affected

dotnetnuke

  • dotnetnuke