8.8
CVSSv3

CVE-2019-10719

Published: 21/06/2019 Updated: 23/06/2019
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 580
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

BlogEngine.NET 3.3.7.0 and previous versions allows Directory Traversal and Remote Code Execution because file creation is mishandled, related to /api/upload and BlogEngine.NET/AppCode/Api/UploadController.cs. NOTE: this issue exists because of an incomplete fix for CVE-2019-6714.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

dotnetblogengine blogengine.net

Exploits

BlogEngineNET versions 336 and 337 suffer from dirPath directory traversal and remote code execution vulnerabilities ...
BlogEngineNET versions 336 and 337 suffer from theme Cookie directory traversal and remote code execution vulnerabilities ...