Advertisement






BlogEngine.NET 3.3.7 Directory Traversal / Remote Code Execution

CVE Category Price Severity
CVE-2019-10719 CWE-22 $5,000 High
Author Risk Exploitation Type Date
Operator8203 Critical Remote 2019-06-19
CPE
cpe:cpe:/a:blogengine:blogengine.net:3.3.7
CVSS EPSS EPSSP
CVSS:4.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H 0.02192 0.50148

CVSS vector description

Our sensors found this exploit at: https://cxsecurity.com/ascii/WLB-2019060121

Below is a copy:

BlogEngine.NET 3.3.7 Directory Traversal / Remote Code Execution
BlogEngine.NET, versions 3.3.7 and earlier, is vulnerable to two separate
Directory Traversal issues that can lead to Remote Code Execution.

CVE-2019-10719 exploits a directory traversal in /api/upload, allowing
users to write files to any location within the web root.  This bypasses
the protection added in version 3.3.7 to prevent CVE-2019-6714.  A user,
with the ability to add images or files to posts, can upload a malicious
PostView.ascx file to the Themes folder.  The code could then be triggered
by setting the theme parameter to the newly create folder.

CVE-2019-10720 exploits a directory traversal in the theme cookie to
trigger a remote code execution.  A user, with the ability to add images or
files to posts, can upload a malicious PostView.ascx file, then trigger the
RCE by setting the theme cookie to ../../App_Data/files.

Disclosure at:
https://www.securitymetrics.com/blog/BlogEngineNET-Directory-Traversal-Remote-Code-Execution-CVE-2019-10719-CVE-2019-10720


Copyright ©2024 Exploitalert.

All trademarks used are properties of their respective owners. By visiting this website you agree to Terms of Use.