S4E just found a high top 10 tcp port service scan
high·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2017-0929 Scanner

CVE-2017-0929 scanner - Server-Side-Request-Forgery (SSRF) vulnerability in DNN (aka DotNetNuke)

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
0
Times Used
by S4E users
0
Assets Scanned
domains & IPs
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2017-0929
7.5
CVSS

DNN (aka DotNetNuke) before 9.2.0 suffers from a Server-Side Request Forgery (SSRF) vulnerability in the DnnImageHandler class. Attackers may be able to access information about internal network resources.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 5, 2026View on NVD →
Detail

DNN (DotNetNuke) is a popular content management system (CMS) that is widely used for website development and management. It is a web-based application that is primarily used for creating and managing web content, such as web pages, images, and other multimedia. DNN is built on the Microsoft .NET platform and is compatible with Windows hosting environments. The system is extensible, customizable, and easy to use for both developers and non-technical users.

However, DNN has had its fair share of security vulnerabilities, one of which is the CVE-2017-0929 vulnerability. This vulnerability affects versions of DNN prior to 9.2.0 and is caused by a Server-Side Request Forgery (SSRF) vulnerability in the DnnImageHandler class. An attacker can exploit this vulnerability to send a specially crafted request to the server, which can allow them to access information about internal network resources that are not normally accessible.

When exploited, the CVE-2017-0929 vulnerability can lead to several detrimental consequences for the victim. An attacker who successfully exploits this vulnerability can access sensitive information about the target organization's internal network, including user credentials, system settings, and other valuable data. This can lead to data breaches, loss of reputation, and financial loss for the victim organization.

At s4e.io, we offer advanced security tools and intelligence to help users protect their digital assets from vulnerabilities like CVE-2017-0929. With our pro features, you can quickly and easily learn about vulnerabilities in your web applications and take proactive measures to protect against them. Don't wait until it's too late - visit s4e.io today to learn more.

 

REFERENCES

Solution Advice

To protect against this vulnerability, it is recommended that users of DNN take the following precautions:

  • Upgrade to the latest version of DNN (9.2.0 or later) to ensure that the vulnerability is patched.
  • Disable the DnnImageHandler class if it is not needed for the website's functionality.
  • Implement access control measures to prevent unauthorized access to sensitive data.
  • Use a web application firewall (WAF) to monitor and filter incoming traffic to the website.
  • Implement strong password policies and educate users on the importance of strong passwords.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.