CVE-2008-7102

DotNetNuke 2.0 through 4.8.4 allows remote attackers to load .ascx files instead of skin files, and possibly access privileged functionality, via unknown vectors related to parameter validation.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
dotnetnukedotnetnuke
2.1.1
dotnetnukedotnetnuke
2.1.2
dotnetnukedotnetnuke
3.0.7
dotnetnukedotnetnuke
3.0.8
dotnetnukedotnetnuke
3.0.11
dotnetnukedotnetnuke
3.1.0
dotnetnukedotnetnuke
3.3.5
dotnetnukedotnetnuke
4.0
dotnetnukedotnetnuke
4.3.5
dotnetnukedotnetnuke
4.4.1
dotnetnukedotnetnuke
4.5.2
dotnetnukedotnetnuke
4.5.4
dotnetnukedotnetnuke
4.5.5
dotnetnukedotnetnuke
4.6.0
dotnetnukedotnetnuke
4.6.1
dotnetnukedotnetnuke
4.6.2
dotnetnukedotnetnuke
4.7.0
dotnetnukedotnetnuke
4.8.0
dotnetnukedotnetnuke
4.8.1
dotnetnukedotnetnuke
4.8.2
dotnetnukedotnetnuke
4.8.3
dotnetnukedotnetnuke
4.8.4
𝑥
= Vulnerable software versions