Products

Solutions

Resources

Partners

Community

Blog

About

QA

Ideas Test

New Community Website

Ordinarily, you'd be at the right spot, but we've recently launched a brand new community website... For the community, by the community.

Yay... Take Me to the Community!

Welcome to the DNN Community Forums, your preferred source of online community support for all things related to DNN.
In order to participate you must be a registered DNNizen

HomeHomeUsing DNN Platf...Using DNN Platf...Administration ...Administration ...Security Bulletin No46 QuestionSecurity Bulletin No46 Question
Previous
 
Next
New Post
2/4/2011 4:25 PM
 

We are running DotNetNuke versions 04.08.02 and 4.09.05  I read the security bulletin below.  The bulletin says all versions, other than 5.0.0-5.6.0, are not affected.  Can anyone confirm that versions 04.08.02 and 04.09.05 are not affected by the described security vulnerability?

http://www.dotnetnuke.com/securitybul...

Much thanks for your help.

 
New Post
2/5/2011 7:11 AM
 
Hello,
Unfortunately I have got the details on that vulnerability incorrect. The report highlighted issues in 2 controls introduced in 5.0, hence why the issue was marked as affecting those versions, but since the publication, another member of the security team highlighted that the uninstall version existed in a different form from earlier versions - at present I'm testing but it appears that it may affect all 4.6.2 versions and above. Once I've validated this, I will update the bulletin and the update service to reflect the changes, but I recommend that you consider upgrading to 5.6.1 as soon as you can. In addition I recommend that you apply the viewstate advice suggested in the blog http://www.dotnetnuke.com/Resources/B...

Apologies,
Cathal
DotNetNuke Security team.

Buy the new Professional DNN7: Open Source .NET CMS Platform book Amazon US
 
New Post
2/7/2011 8:20 AM
 
Thank you, Cathal.  I'm grateful for the information, even though it's not what I wanted to hear.

SJG
 
Previous
 
Next
HomeHomeUsing DNN Platf...Using DNN Platf...Administration ...Administration ...Security Bulletin No46 QuestionSecurity Bulletin No46 Question


These Forums are dedicated to discussion of DNN Platform and Evoq Solutions.

For the benefit of the community and to protect the integrity of the ecosystem, please observe the following posting guidelines:

  1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DNN.
  2. No vendor trolling / poaching. If someone posts about a vendor issue, allow the vendor or other customers to respond. Any post that looks like trolling / poaching will be removed.
  3. Discussion or promotion of DNN Platform product releases under a different brand name are strictly prohibited.
  4. No Flaming or Trolling.
  5. No Profanity, Racism, or Prejudice.
  6. Site Moderators have the final word on approving / removing a thread or post or comment.
  7. English language posting only, please.
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out