CVE-2019-10717

HIGH NUCLEI

BlogEngine.NET 3.3.7.0 - Path Traversal via File Manager API Path Parameter

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2019-10717 has a Nuclei detection template available — see the Nuclei card below for the Shodan/FOFA recon queries.

Description

BlogEngine.NET 3.3.7.0 allows /api/filemanager Directory Traversal via the path parameter.

Nuclei Templates (1)

BlogEngine.NET 3.3.7.0 - Local File Inclusion
HIGHVERIFIEDby arafatansari
Shodan: http.html:"Blogengine.net" || http.html:"blogengine.net"
FOFA: body="blogengine.net"

References (3)

Core 3
Core References
Patch, Third Party Advisory x_refsource_misc
https://github.com/rxtur/BlogEngine.NET/commits/master
Mailing List, Third Party Advisory mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2019/Jun/44

Scores

CVSS v3 7.1
EPSS 0.0540
EPSS Percentile 91.6%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N

Details

CWE
CWE-22
Status published
Products (1)
dotnetblogengine/blogengine.net 3.3.7.0
Published Jul 03, 2019
Tracked Since Feb 18, 2026