72230 : DotNetNuke ASPX File Upload Arbitrary Code Execution Printer | http://osvdb.org/72230 | Email This | Edit Vulnerability
DotNetNuke contains a flaw related to a failure to sufficiently enforce authorization checks. This may allow a remote attacker to upload an ASPX file and use it to execute arbitrary code.
Upgrade to version 5.6.1 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.
NVD does not currently have a CVSSv2 score assigned.
Add Comment Hide Add Comment