Security Software Zone Security Software Zone
Home Contact Us
Search in
Forum SecurityToolbox Submit Software
Security Software Zone Login
Security Software Categories
News - Articles - Reviews
Free Newsletter
Join our mailing list and receive
security software news and
advice from our experts.
Submit
  Security Software Zone » Software Reviews » General Security » Two Hyper-Critical Security Flaws Discovered and Patched by PowerDNN

Two Hyper-Critical Security Flaws Discovered and Patched by PowerDNN

Category: General Security
Published: 05/22/2008, 12:19  
Editor: Catalin Buda
 
Print article
Send to a friend
Search in reviews
Two hyper-critical security flaws in the standard DotNetNuke framework have been discovered by the leader in DotNetNuke Services and Solutions, PowerDNN.

Two Hyper-Critical security flaws in the standard DotNetNuke Framework have been discovered by the PowerDNN Engineering Team, as lead by Mr. Tony Valenti and Mr. Joseph Ravioli, as of Yesterday evening at 9:47PM US Central Time. These security flaws, if left unpatched, would allow any website visitor to alter the DotNetNuke web.config file as well as remotely execute SQL scripts against the DotNetNuke database. To create patches for all affected versions of DotNetNuke, since last night, the entire PowerDNN engineering team has been working around the clock. These patches have been created and deployed to all PowerDNN customers, as of 7:42PM US Central Time.

Regarding these vulnerabilities, PowerDNN will be gradually releasing more details to the general community.
It is especially important for them to approach this issue in a sensitive and confidential manner, because of the large number of people running un-patched, standard versions of DotNetNuke. An online DotNetNuke Website Scanner, to aide with this, is now available from PowerDNN DNN Hosting.

PowerDNN.com, founded in 2002, is the full circle DotNetNuke solutions provider, servicing organizations ranging from small businesses to Fortune 500 Companies to the Federal Government of the United States of America. PowerDNN, specializing in high-reliability, business-critical DotNetNuke solutions, is the clear choice of business and technology experts who demand exceptional customer service and enterprise engineering support for DotNetNuke.
Bookmark to:
Add 'Two Hyper-Critical Security Flaws Discovered and Patched by PowerDNN' to Del.icio.us Add 'Two Hyper-Critical Security Flaws Discovered and Patched by PowerDNN' to digg Add 'Two Hyper-Critical Security Flaws Discovered and Patched by PowerDNN' to FURL Add 'Two Hyper-Critical Security Flaws Discovered and Patched by PowerDNN' to reddit Add 'Two Hyper-Critical Security Flaws Discovered and Patched by PowerDNN' to Technorati Add 'Two Hyper-Critical Security Flaws Discovered and Patched by PowerDNN' to Yahoo My Web Add 'Two Hyper-Critical Security Flaws Discovered and Patched by PowerDNN' to Stumble Upon Add 'Two Hyper-Critical Security Flaws Discovered and Patched by PowerDNN' to Google Bookmarks Add 'Two Hyper-Critical Security Flaws Discovered and Patched by PowerDNN' to RawSugar Add 'Two Hyper-Critical Security Flaws Discovered and Patched by PowerDNN' to Squidoo Add 'Two Hyper-Critical Security Flaws Discovered and Patched by PowerDNN' to Spurl Add 'Two Hyper-Critical Security Flaws Discovered and Patched by PowerDNN' to Netvouz Add 'Two Hyper-Critical Security Flaws Discovered and Patched by PowerDNN' to Rojo Add 'Two Hyper-Critical Security Flaws Discovered and Patched by PowerDNN' to Bloglines Add 'Two Hyper-Critical Security Flaws Discovered and Patched by PowerDNN' to Tailrank
Add comment
Security Software Zone is not responsible for the content of these User comments. The views and opinions expressed are those of the individual poster and not the Security Software Zone.
User comments (3):
1. Power DNN are scammers!
by Tom on 05/23/2008, 19:21
Stay away from PowerDNN as they are scammers & will risk the security of your website.
2. Power DNN are scammers!
by Tom on 05/23/2008, 19:22
Stay away from PowerDNN as they are scammers & will risk the security of your website.
3. Cancelled Account
by Cancelled Account on 06/18/2008, 19:47
Cancelled my account with this company. They lost my respect by trying to make a buck out of a security issue, and also inserting hidden links in their customers sites. Better off hosting with a reputable web host.
 
Reviews related to Two Hyper-Critical Security Flaws Discovered and Patched by PowerDNN
 

New Frontier of Fraud Management to be discussed by ovation CEO
 iovation is leading the way in providing innovative reputation systems that protect hundreds of online services and millions of consumers from all forms of online fraud and abuse, as online merchants require stronger fraud management tools to defend their online services from more sophisticated and organized fraud tactics.
Read More >
02/28/2008, 17:24
 

Access Management and Continuous Compliance Session Presented by Courion
 The impact of increasingly collaborative and virtualized work environments on organizations' ability to establish appropriate risk-based governance and controls will be examined by the session, "Ensuring Proper Identity and Access Management Controls for Continuous Compliance".
Read More >
05/07/2008, 08:07
 

New Options for XLi GPS Synchronized Time and Frequency System Announced
 New option modules for its XLi/XLi SAASM Time and Frequency System have been announced by a worldwide leader in precise time and frequency technologies that accelerate the deployment and enable the management of next generation networks, Symmetricom, Inc.
Read More >
06/05/2008, 10:07
 

Woomail is agreed by Republicans and Democrats
 Political candidates are propelled to the forefront by the speed at which they can share information, ideas and platforms, while maintaining the privacy of each message as necessary, in the face of a new digital frontier.
Read More >
02/20/2008, 13:03
 

Major Spam Ring Shut Down
 Stopping what the Federal Trade Commission (FTC) says was one of the most prolific spam gangs on the Internet, an Illinois, USA, district court ordered on Tuesday a vast international spam network to shut down.
Read More >
10/20/2008, 12:38

Sponsored