0xLanks

2 exploits Active since Dec 2022
CVE-2022-41417 WRITEUP CRITICAL WRITEUP
BlogEngine.NET <3.3.8.0 - Path Traversal
BlogEngine.NET v3.3.8.0 allows an attacker to create any folder with "files" prefix under ~/App_Data/.
CVSS 9.8
CVE-2022-41418 WRITEUP HIGH WRITEUP
BlogEngine.NET <3.3.8.0 - RCE
An issue in the component BlogEngine/BlogEngine.NET/AppCode/Api/UploadController.cs of BlogEngine.NET v3.3.8.0 allows attackers to execute arbitrary code via uploading a crafted PNG file.
CVSS 7.2