CVE-2017-9822

8.8HIGH

DNN (aka DotNetNuke) before 9.1.1 has Remote Code Execution via a cookie, aka "2017-08 (Critical) Possible remote code execution on DNN sites."

发布于: 7/20/2017更新于: 10/22/2025

CISA已知被利用漏洞

DotNetNuke (DNN) contains a vulnerability that may allow for remote code execution via cookie deserialization.

所需操作:

Apply updates per vendor instructions.

截止日期:

2022-05-03

已知勒索软件使用

描述

DNN (aka DotNetNuke) before 9.1.1 has Remote Code Execution via a cookie, aka "2017-08 (Critical) Possible remote code execution on DNN sites."

AI分析AI驱动

受影响产品

dnnsoftwaredotnetnuke

可用漏洞利用 (1)

参考资料