6.5
CVSSv2

CVE-2019-10720

Published: 21/06/2019 Updated: 29/06/2020
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 580
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

BlogEngine.NET 3.3.7.0 and previous versions allows Directory Traversal and Remote Code Execution via the theme cookie to the File Manager. NOTE: this issue exists because of an incomplete fix for CVE-2019-6714.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

blogengine blogengine.net

Exploits

BlogEngineNET versions 336 and 337 suffer from theme Cookie directory traversal and remote code execution vulnerabilities ...