HTTP: DotNetNuke DNNarticle Module Directory Traversal

This signature detects attempts to exploit a known vulnerability against DotNetNuke DNNarticle Module. A successful attack can lead to directory traversal.

Extended Description

The DNNArticle module 11 for DNN (formerly DotNetNuke) allows remote attackers to read the web.config file, and consequently discover database credentials, via the /GetCSS.ashx/?CP=%2fweb.config URI.

Affected Products

Zldnn dnnarticle

References

CVE: CVE-2018-9126

Short Name
HTTP:DIR:DOTNETNUKE-DNNA-DIR
Severity
Minor
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
CVE-2018-9126 DNNarticle Directory DotNetNuke Module Traversal
Release Date
04/03/2019
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3337
False Positive
Unknown
Vendors

Zldnn

CVSS Score

5.0

Found a potential security threat?