packetstormsecurity.com
http://packetstormsecurity.com/files/151063/BlogEngine-3.3-XML-External-Entity-Injection.html CVE-2018-14485
CRITICAL
BlogEngine 3.3 - XML External Entity Injection
Record summary
CVE-2018-14485 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit.
Description
BlogEngine.NET 3.3 allows XXE attacks via the POST body to metaweblog.axd.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBBlogEngine 3.3 - XML External Entity InjectionExploitDB exploitby NetsparkerNot analyzed1 file
References
4github.com
https://github.com/rxtur/BlogEngine.NET/commits/master nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2018-14485 exploit-db.com
https://www.exploit-db.com/exploits/46106