Loading vulnerability details…
CVSS v3.1
N/A
EPSS
1.23%
Published
Nov 29, 2009
Modified
Apr 24, 2026
Public PoC / Exploit
All weaponized →No public PoC or exploit code indexed for this CVE.
Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
The install wizard in DotNetNuke 4.0 through 5.1.4 does not prevent anonymous users from accessing functionality related to determination of the need for an upgrade, which allows remote attackers to access version information and possibly other sensitive information.
Weaknesses (CWE)
Affected Products (24)
References (8)