Record summary

CVE-2019-10717 has a selected CVSS score of 7.1 (high); EIP currently links 1 Nuclei template.

Description

BlogEngine.NET 3.3.7.0 allows /api/filemanager Directory Traversal via the path parameter.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryHIGHBlogEngine.NET 3.3.7.0 - Local File InclusionCVSS 7.1

BlogEngine.NET 3.3.7.0 allows /api/filemanager local file inclusion via the path parameter

Impact

An attacker can exploit this vulnerability to read sensitive files, execute arbitrary code, or launch further attacks.

Remediation

Upgrade to a patched version of BlogEngine.NET or apply the vendor-supplied patch to mitigate this vulnerability.

WeaknessesCWE-22
Authorsarafatansari
Template tagscvecve2019seclistsblogenginelfitraversaldotnetblogenginevuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N
CPE: cpe:2.3:a:dotnetblogengine:blogengine.net:3.3.7.0:*:*:*:*:*:*:*
Shodan: http.html:"Blogengine.net"
Shodan: http.html:"blogengine.net"
FOFA: body="blogengine.net"

Source: ProjectDiscovery

References

4