Install wizard information leakage

Published: September 10, 2008

Edited : Febuary 24, 2009 - Added note about 5.0 missing relevant code.

Version: 1.1

Maximum Severity Rating: Low

Background

When a DotNetNuke portal is installed the version number if displayed on the link to first access the portal.

Issue Summary

Under some circumstances it was possible to view the install wizard page, allowing potential hackers to view the portal number. This information could be useful to hackers attempting to profile an application. 

Mitigating factors

N/a

Affected DotNetNuke versions

  • 4.0 - 4.8.4
  • 5.0 - Note: the code was put in place for 4.9, but was not correctly merged into the 5.0 (cambrian) branch. This issue was resolved in 5.0.1

Non-Affected Versions:

  • All other versions

Fix(s) for issue

To fix this problem, you are recommended to update to the latest version of DotNetNuke (4.9.2/5.0.1 at time of writing)

Acknowledgments

N/A

Security Policy


Click here to read more details on the DotNetnuke Security Policy

 

Attend A Webinar
Start  Professional Edition Trial
Have Someone Contact Me

Like Us on Facebook Join our Network on LinkedIn Follow DNN Corporate on Twitter Follow DNN on Twitter

Advertisers

Sponsors

DotNetNuke Corporation

DotNetNuke (DNN) provides a suite of solutions that make designing, building and managing feature-rich sites and communities fast, easy and cost-effective. The DotNetNuke Platform CMS is the foundation for more than one million websites worldwide. DNN Social, our newest solution, enables businesses to create immersive, interactive communities. Thousands of organizations like True Value Hardware, Bose, Cornell University, Glacier Water, Dannon, Delphi, USAA, NASCAR, Northern Health and the City of Denver have leveraged DNN to deploy highly engaging business- critical websites. Our rapid growth in product sales and deployments resulted in DotNetNuke Corp. being named one of the fastest growing private companies in America by Inc. Magazine in 2011 and 2012.