HomeHomeOur CommunityOur CommunityCommunity Membe...Community Membe...Any PowerDNN users? Any PowerDNN users?
Previous
 
Next
New Post
5/21/2008 8:24 AM
 

Anyone get the PowerDNN email recently? I've not seen anything in the forums about it yet but wondering if the core team is aware and working on it?

 
New Post
5/21/2008 8:30 AM
 

I think I'm only rated "miniPowerDNN"

 
New Post
5/21/2008 8:32 AM
 

Yes, I have one of my sites hosted with them and received the email this morning.

As of Yesterday evening at 9:47PM US Central Time, the PowerDNN Engineering Team, discovered two Hyper-Critical security flaws in the standard DotNetNuke Framework.  If left unpatched, these security flaws would allow any website visitor to alter your web.config file as well as remotely execute SQL scripts against your database.  Since last night, our entire engineering team has been working around the clock to create patches for all affected versions of DotNetNuke.  As of 7:42PM US Central Time, these patches have been created and deployed to all PowerDNN customers.

 
New Post
5/21/2008 8:36 AM
 

Just got one.  Hopefully we will be hearing from the core team soon to validate the threat..

 
New Post
5/21/2008 9:05 AM
 

Yeah, I was hesitating on posting too many details to the forums yet but since PowerDNN isn't giving any details no one seems to be sure of anything. I'm currently ftp'ing one of my sites down to look for modified dates. The only other options seem to be running a netowrk scanner on a site and then scanning it with their tool or doing a complete backup before paying them the $20 to patch it and see what they changed. I would hope they are communicating with the core team on this. Would be really $hitty to keep it to themselves and charge for fixing it.

 
Previous
 
Next
HomeHomeOur CommunityOur CommunityCommunity Membe...Community Membe...Any PowerDNN users? Any PowerDNN users?


Forum Policy

These Discussion Forums are dedicated to the discussion of the DotNetNuke Web Application Framework.

For the benefit of the community and to protect the integrity of the project, please observe the following posting guidelines:

1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DotNetNuke.
2. Discussion or promotion of DotNetNuke product releases under a different brand name are strictly prohibited.
3. No Flaming or Trolling.
4. No Profanity, Racism, or Prejudice.
5. Site Moderators have the final word on approving/removing a thread or post or comment.
6. English language posting only, please.

Attend A Webinar
Try An Online Demo
Download DotNetNuke Professional Edition Trial
Have Someone Contact Me

Like Us on Facebook Join our Network on LinkedIn Follow DNN Corporate on Twitter Follow DNN on Twitter

Advertisers

DotNetNuke Scoop!

Sponsors

DotNetNuke Corporation

DotNetNuke Corp. is the steward of the DotNetNuke open source project, the most widely adopted Web Content Management Platform for building web sites and web applications on Microsoft .NET. Organizations use DotNetNuke to quickly develop and deploy interactive and dynamic web sites, intranets, extranets and web applications. The DotNetNuke platform is available in a free Community and subscription-based Professional and Enterprise Editions with an Elite Support option. DotNetNuke Corp. also operates Snowcovered.com where users purchase third party apps for the platform.