Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2008-6540

DotNetNuke before 4.8.2, during installation or upgrade, does not warn the administrator when the default (1) ValidationKey and (2) DecryptionKey values cannot be modified in the web.config file, which allows remote attackers to bypass intended access restrictions by using the default keys.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.052
EPSS Ranking 89.5%
CVSS Severity
CVSS v2 Score 5.1
Products affected by CVE-2008-6540


Contact Us

Shodan ® - All rights reserved