Search
Purchase DNN Modules
Our success stories
ThermaPro Solutions (www.thermaprosolutions.com) is a leading company in Montreal, Canada - providing bed bugs detection and extermination services.
DotNetNuke (DNN) Resource Search
Only DNN - DotNetNuke Blog
FeedBurner Subscribe to Ismet Dumlupinar's DotNetNuke Blog



DotNetNuke 5.6.2 introduces a legacy security issue regarding Core Permission Provider via User Profile. An authenticated user could access admin level rights from user profile page and this issue could be one of the major security issues of DotNetNuke.



If you are using an earlier version of DotNetNuke i would suggest either upgrading to DotNetNuke 5.6.1 for now, or if you are using latest build then go ahead and apply the temporary workaround from a DotNetNuke Partner...



The issue is still being discussed under following topic >>

The temporary workaround can be applied by replacing a core permission provider dll of DNN.

Post Rating

Comments

There are currently no comments, be the first to post one.

Post Comment

Name (required)

Email (required)

Website

CAPTCHA image
Enter the code shown above:




Web Hosting Blogs - BlogCatalog Blog Directory

blogarama - the blog directory


Web Development blogs & blog posts

2007 - 2011 www.onlydnn.com   |  Privacy Statement  |  Terms Of Use  Xhtml 1.0  CSS 2.0