EIP-2026-100643
PRE-CVEBlogEngine.NET 3.3.6/3.3.7 - 'path' Directory Traversal
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-100643. PoCs published by Aaron Bishop.
AI-analyzed exploit summary This exploit demonstrates a directory traversal vulnerability in BlogEngine.NET by sending a crafted GET request to the /api/filemanager endpoint with a path parameter containing ../ sequences. It includes functionality to authenticate, traverse directories, and output file paths to a specified file.
Description
BlogEngine.NET 3.3.6/3.3.7 - 'path' Directory Traversal
Exploits (1)
This exploit demonstrates a directory traversal vulnerability in BlogEngine.NET by sending a crafted GET request to the /api/filemanager endpoint with a path parameter containing ../ sequences. It includes functionality to authenticate, traverse directories, and output file paths to a specified file.