Note:
This project will be discontinued after December 13, 2021. [more]
Product:
Blogengine\.net
(Blogengine)Repositories |
Unknown: This might be proprietary software. |
#Vulnerabilities | 13 |
Date | Id | Summary | Products | Score | Patch | Annotated |
---|---|---|---|---|---|---|
2019-06-21 | CVE-2019-10720 | BlogEngine.NET 3.3.7.0 and earlier allows Directory Traversal and Remote Code Execution via the theme cookie to the File Manager. NOTE: this issue exists because of an incomplete fix for CVE-2019-6714. | Blogengine\.net | N/A | ||
2019-03-21 | CVE-2019-6714 | An issue was discovered in BlogEngine.NET through 3.3.6.0. A path traversal and Local File Inclusion vulnerability in PostList.ascx.cs can cause unauthenticated users to load a PostView.ascx component from a potentially untrusted location on the local filesystem. This is especially dangerous if an authenticated user uploads a PostView.ascx file using the file manager utility, which is currently allowed. This results in remote code execution for an authenticated user. | Blogengine\.net | 9.8 | ||
2019-05-07 | CVE-2018-14485 | BlogEngine.NET 3.3 allows XXE attacks via the POST body to metaweblog.axd. | Blogengine\.net | 9.8 |