CVE-2019-10717

HIGH NUCLEI

Dotnetblogengine Blogengine.net - Path Traversal

Title source: rule

Description

BlogEngine.NET 3.3.7.0 allows /api/filemanager Directory Traversal via the path parameter.

Nuclei Templates (1)

BlogEngine.NET 3.3.7.0 - Local File Inclusion
HIGHVERIFIEDby arafatansari
Shodan: http.html:"Blogengine.net" || http.html:"blogengine.net"
FOFA: body="blogengine.net"

Scores

CVSS v3 7.1
EPSS 0.1218
EPSS Percentile 93.9%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N

Details

CWE
CWE-22
Status published
Products (1)
dotnetblogengine/blogengine.net 3.3.7.0
Published Jul 03, 2019
Tracked Since Feb 18, 2026