Unrated severityNVD Advisory· Published Dec 9, 2010· Updated Apr 29, 2026
CVE-2010-4514
CVE-2010-4514
Description
Cross-site scripting (XSS) vulnerability in Install/InstallWizard.aspx in DotNetNuke 5.05.01 and 5.06.00 allows remote attackers to inject arbitrary web script or HTML via the __VIEWSTATE parameter. NOTE: some of these details are obtained from third party information.
Affected products
2cpe:2.3:a:dnnsoftware:dotnetnuke:5.05.01:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:dnnsoftware:dotnetnuke:5.05.01:*:*:*:*:*:*:*
- cpe:2.3:a:dnnsoftware:dotnetnuke:5.06.00:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- packetstormsecurity.org/files/view/96378/PR10-19.txtnvdExploit
- www.procheckup.com/vulnerability_manager/vulnerabilities/pr10-19nvdExploit
- www.securityfocus.com/bid/45180nvdExploit
- www.securitytracker.com/idnvdExploit
- secunia.com/advisories/42478nvdVendor Advisory
News mentions
0No linked articles in our index yet.