Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
dotnetblogengine vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2013-6953
BlogEngine.NET 2.8.0.0 and previous versions allows remote malicious users to read usernames and password hashes via a request for the sioc.axd file.
Dotnetblogengine Blogengine.net 1.5
Dotnetblogengine Blogengine.net 1.6
Dotnetblogengine Blogengine.net 2.0
Dotnetblogengine Blogengine.net 2.5
Dotnetblogengine Blogengine.net 2.7
Dotnetblogengine Blogengine.net 1.4.5
Dotnetblogengine Blogengine.net 2.6
Dotnetblogengine Blogengine.net
NA
CVE-2008-6476
Cross-site scripting (XSS) vulnerability in blog/search.aspx in BlogEngine.NET allows remote malicious users to inject arbitrary web script or HTML via the q parameter.
Dotnetblogengine Blogengine.net
1 EDB exploit
7.5
CVSSv3
CVE-2019-10718
BlogEngine.NET 3.3.7.0 and previous versions allows XML External Entity Blind Injection, related to pingback.axd and BlogEngine.Core/Web/HttpHandlers/PingbackHandler.cs.
Dotnetblogengine Blogengine.net
8.8
CVSSv3
CVE-2019-10719
BlogEngine.NET 3.3.7.0 and previous versions allows Directory Traversal and Remote Code Execution because file creation is mishandled, related to /api/upload and BlogEngine.NET/AppCode/Api/UploadController.cs. NOTE: this issue exists because of an incomplete fix for CVE-2019-6714...
Dotnetblogengine Blogengine.net
7.5
CVSSv3
CVE-2019-11392
BlogEngine.NET 3.3.7 and previous versions allows XXE via an apml file to syndication.axd.
Dotnetblogengine Blogengine.net
7.1
CVSSv3
CVE-2019-10717
BlogEngine.NET 3.3.7.0 allows /api/filemanager Directory Traversal via the path parameter.
Dotnetblogengine Blogengine.net 3.3.7.0
6.1
CVSSv3
CVE-2019-10721
BlogEngine.NET 3.3.7.0 allows a Client Side URL Redirect via the ReturnUrl parameter, related to BlogEngine/BlogEngine.Core/Services/Security/Security.cs, login.aspx, and register.aspx.
Dotnetblogengine Blogengine.net 3.3.7.0
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
deserialization
CVE-2024-4040
cross-site scripting
CVE-2023-25790
CVE-2024-2961
XML external entity
CVE-2024-26926
CVE-2024-32806
CVE-2024-32711
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started