Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2017-9822 — Detailed analysis and proof-of-concept exploit for CVE-2017-9822, an XXE/insecure deserialization vulnerability in DotNetNuke CMS leading to remote code execution via cookie manipulation. | Kitploit
Tools/GitHubGitHub/tranphuc2005/cve-2017-9822
Vulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingPayload DevelopmentBinary Exploitation
GitHubtranphuc2005/cve-2017-9822

CVE-2017-9822

Detailed analysis and proof-of-concept exploit for CVE-2017-9822, an XXE/insecure deserialization vulnerability in DotNetNuke CMS leading to remote code execution via cookie manipulation.

View Repository
41 year agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2017-9822

DotNetNuke (often abbreviated as DNN) is a CMS (Content Management System) platform and web application framework based on Microsoft's ASP.NET technology.

Key Information

  • Affected Product: DotNetNuke (DNN Platform) – a popular .NET CMS/portal.

  • Disclosure Date: July 2017.

  • Severity: Critical (CVSS ~9.8).

  • Vulnerability Type: XML External Entity (XXE) / Insecure Deserialization → Remote Code Execution (RCE).

  • Affected Versions: Prior to version 9.1.1, capable of remote code execution through cookie

Installation Guide

Here I am using Windows 10 to set up and debug the program. The version I am installing is 9.1.0. You can refer to the installation guide Here. And the result after completion is:

1

Analysis

1

  • According to the reports I have read, this vulnerability lies in the cookie handling of DotNetNetNuke

  • DNN uses a safe deserialization method (unsafe deserialization) for the DNNPersonalization cookie

1

Debug

  • Here I use dnSpy, which is a decompiler and debugger for .NET applications (C#, VB.NET, F#...). It allows you to view, analyze, and edit source code from compiled files such as .dll or .exe written in .NET. You can install it Here. We need to download 2 versions for debugging purposes.

1

  • First, open DotNetNuke.dll with the 32-bit version and select Edit Assembly Attributes (C#)

1

  • Then replace the line
[assembly: Debuggable(DebuggableAttribute.DebuggingModes.IgnoreSymbolStoreSequencePoints)]
  • With
[assembly: Debuggable(DebuggableAttribute.DebuggingModes.Default |
DebuggableAttribute.DebuggingModes.DisableOptimizations |
DebuggableAttribute.DebuggingModes.IgnoreSymbolStoreSequencePoints |
DebuggableAttribute.DebuggingModes.EnableEditAndContinue)]

1

Then save.

  • Open the 64-bit version as Administrator and select Attach to Process

1

  • Next, select w3wp.exe

1

The reason for choosing w3wp.exe is:

  • w3wp.exe = IIS Worker Process.

  • It is the execution process of the Application Pool in IIS.

  • When an HTTP request is sent to the website, IIS creates or reuses a w3wp.exe to process that request (running ASP.NET code, handling modules, middleware, database connections, etc.).

  • Each Application Pool may have one or more w3wp.exe processes depending on configuration (web garden, recycling).

Next, select Debug -> Window -> Modules

1

After that, the Modules will appear. Right-click on any one and select Open All Modules

1

Finally, all assemblies related to DNN will appear

1

  • Go inside DotNetNuke.dll -> PersonalizationController#LoadProfile(int, int)

1

This function is used to load the user's personalization data (profile) in the DNN portal.

  • If the user is logged in → load profile from database + cache.

  • If the user is anonymous (not logged in) → load profile from cookie DNNPersonalization.

Here we should focus on DNNPersonalization

  • If userId is invalid (anonymous user).

  • Check if the request has a cookie DNNPersonalization.

  • If yes → get the XML value from this cookie.

  • We will send a 404 request to the website and use any DNNPersonalization, use dnSpy to set a Breakpoint at DotNetNuke.dll –> PersonalizationController#LoadProfile(int, int) then we can debug

1

1

  • In the Call Stack, let's focus on analyzing the class PortalSettings

1

  • The notable thing here is that it uses an if condition to check if the current request is IsAuthenticated or not

  • And while the request we sent is a 404 -> unauthenticated

  • Continue in the Call Stack, focusing on Handle404OrException

1

  • Here it will check if the current request context.User is null, if so, assign context.User to the current thread user

1

1

  • We can see in Handle404OrException the variable IsAuthenticated now has the value true and the user is the IIS server user, so the request is executed as an authenticated user.

  • The reason for the issue lies in this code snippet

else if (transfer)
{
	if (context.User == null)
	{
		context.User = Thread.CurrentPrincipal;
	}
	response.TrySkipIisCustomErrors = true;
	IHttpHandler handler = new CDefault();
	context.Handler = handler;
	server.Transfer("~/" + text, true);
}
  • If context.User is not set → assign Thread.CurrentPrincipal (i.e., the current thread's identity).

  • This allows the request to have user/role information when processing further.

=> When we pass any content into the cookie with the DNNPersonalization variable, it will execute as a normal user.

Next, look at the cookie processing direction

  • Still in DotNetNuke.dll –> PersonalizationController#LoadProfile(int, int)

  • We see the variable text receives the value from the cookie value and then is used as input for Globals.DeserializeHashTableXml()

1

  • Go into Globals.DeserializeHashTableXml()

1

The function DeserializeHashTableXml has the task:

Download Tool