CRITICAL
An issue was discovered in BlogEngine.NET through 3.3.6.0
Published Mar 17, 2019
9.8
CRITICALCVSS 3.0
EPSS 31.72%
Description
An issue was discovered in BlogEngine.NET through 3.3.6.0. A path traversal and Local File Inclusion vulnerability in PostList.ascx.cs can cause unauthenticated users to load a PostView.ascx component from a potentially untrusted location on the local filesystem. This is especially dangerous if an authenticated user uploads a PostView.ascx file using the file manager utility, which is currently allowed. This results in remote code execution for an authenticated user.
Affected products
No data.
- ≤ 3.3.6.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (5)
- http://packetstormsecurity.com/files/151628/BlogEngine.NET-3.3.6-Directory-Traversal-Remote-Code-Execution.html x_refsource_MISCExploitThird Party AdvisoryVDB Entry
- http://seclists.org/fulldisclosure/2019/Jun/26 mailing-listx_refsource_FULLDISC
- https://blogengine.io/ x_refsource_MISCProduct
- https://github.com/rxtur/BlogEngine.NET/ x_refsource_MISCProductThird Party Advisory
- https://www.exploit-db.com/exploits/46353/ exploitx_refsource_EXPLOIT-DBThird Party AdvisoryVDB Entry
| Link | Providers | Tags |
|---|---|---|
| http://packetstormsecurity.com/files/151628/BlogEngine.NET-3.3.6-Directory-Traversal-Remote-Code-Execution.html | x_refsource_MISCExploitThird Party AdvisoryVDB Entry | |
| http://seclists.org/fulldisclosure/2019/Jun/26 | mailing-listx_refsource_FULLDISC | |
| https://blogengine.io/ | x_refsource_MISCProduct | |
| https://github.com/rxtur/BlogEngine.NET/ | x_refsource_MISCProductThird Party Advisory | |
| https://www.exploit-db.com/exploits/46353/ | exploitx_refsource_EXPLOIT-DBThird Party AdvisoryVDB Entry |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Mar 17, 2019
Updated Aug 4, 2024
Reserved Jan 23, 2019
Link CVE-2019-6714
CISA Vulnrichment
Updated n/a