Critical severity9.8NVD Advisory· Published Apr 4, 2018· Updated Jun 17, 2026
CVE-2018-9126
CVE-2018-9126
Description
The DNNArticle module 11 for DNN (formerly DotNetNuke) allows remote attackers to read the web.config file, and consequently discover database credentials, via the /GetCSS.ashx/?CP=%2fweb.config URI.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: =11
Patches
Vulnerability mechanics
References
2- packetstormsecurity.com/files/146999/DotNetNuke-DNNarticle-Directory-Traversal.htmlnvdExploitThird Party AdvisoryVDB Entry
- www.exploit-db.com/exploits/44414/nvdExploitThird Party AdvisoryVDB Entry
News mentions
0No linked articles in our index yet.