Release date:
Updated on: 2013-08-17
Affected Systems:
DotNetNuke DNNArticle 10.0
Description:
--------------------------------------------------------------------------------
Bugtraq id: 61788
CVE (CAN) ID: CVE-2013-5117
DotNetNuke DNNArticle is the CMS and article management module of DNN.
DNNArticle 10.0 and earlier versions do not correctly verify the effectiveness of the categoryid parameter value. The SQL injection vulnerability exists. After successful exploitation, remote attackers can perform unauthorized database operations.
<* Source: Sajjad Pourali
*>
Test method:
--------------------------------------------------------------------------------
Alert
The following procedures (methods) may be offensive and are intended only for security research and teaching. Users are at your own risk!
Http://www.example.com/desktopmodules/dnnarticle/dnnarticlerss.aspx? Moduleid = 0 & amp; categoryid = 1 + or + 1 = @ version
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
DotNetNuke
----------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Www.dnnarticle.com