EIP-2026-100642
PRE-CVEBlogEngine.NET 3.3.6/3.3.7 - 'dirPath' Directory Traversal / Remote Code Execution
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-100642. PoCs published by Aaron Bishop.
AI-analyzed exploit summary This exploit leverages a directory traversal vulnerability in BlogEngine.NET's file upload functionality to achieve remote code execution by uploading a malicious PostView.ascx file. The exploit includes a reverse shell payload that connects back to an attacker-controlled host.
Description
BlogEngine.NET 3.3.6/3.3.7 - 'dirPath' Directory Traversal / Remote Code Execution
Exploits (1)
This exploit leverages a directory traversal vulnerability in BlogEngine.NET's file upload functionality to achieve remote code execution by uploading a malicious PostView.ascx file. The exploit includes a reverse shell payload that connects back to an attacker-controlled host.