CVE-2008-7102

DotNetNuke 2.0 through 4.8.4 allows remote attackers to load .ascx files instead of skin files, and possibly access privileged functionality, via unknown vectors related to parameter validation.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 70%
VendorProductVersion
dotnetnukedotnetnuke
2.1.1
dotnetnukedotnetnuke
2.1.2
dotnetnukedotnetnuke
3.0.7
dotnetnukedotnetnuke
3.0.8
dotnetnukedotnetnuke
3.0.11
dotnetnukedotnetnuke
3.1.0
dotnetnukedotnetnuke
3.3.5
dotnetnukedotnetnuke
4.0
dotnetnukedotnetnuke
4.3.5
dotnetnukedotnetnuke
4.4.1
dotnetnukedotnetnuke
4.5.2
dotnetnukedotnetnuke
4.5.4
dotnetnukedotnetnuke
4.5.5
dotnetnukedotnetnuke
4.6.0
dotnetnukedotnetnuke
4.6.1
dotnetnukedotnetnuke
4.6.2
dotnetnukedotnetnuke
4.7.0
dotnetnukedotnetnuke
4.8.0
dotnetnukedotnetnuke
4.8.1
dotnetnukedotnetnuke
4.8.2
dotnetnukedotnetnuke
4.8.3
dotnetnukedotnetnuke
4.8.4
𝑥
= Vulnerable software versions