[prev in list] [next in list] [prev in thread] [next in thread]
List: full-disclosure
Subject: [FD] BlogEngine.NET Directory traversal + RCE
From: aaron bishop <abishop () linux ! com>
Date: 2019-06-17 23:33:25
Message-ID: CA+Ma4JvVy9MCubANTczOQ5uv1OdAYnTG8meFaPM3ZyRA3gsKFg () mail ! gmail ! com
[Download RAW message or body]
BlogEngine.NET, versions 3.3.7 and earlier, is vulnerable to two separate
Directory Traversal issues that can lead to Remote Code Execution.
CVE-2019-10719 exploits a directory traversal in /api/upload, allowing
users to write files to any location within the web root. This bypasses
the protection added in version 3.3.7 to prevent CVE-2019-6714. A user,
with the ability to add images or files to posts, can upload a malicious
PostView.ascx file to the Themes folder. The code could then be triggered
by setting the theme parameter to the newly create folder.
CVE-2019-10720 exploits a directory traversal in the theme cookie to
trigger a remote code execution. A user, with the ability to add images or
files to posts, can upload a malicious PostView.ascx file, then trigger the
RCE by setting the theme cookie to ../../App_Data/files.
Disclosure at:
https://www.securitymetrics.com/blog/BlogEngineNET-Directory-Traversal-Remote-Code-Execution-CVE-2019-10719-CVE-2019-10720
_______________________________________________
Sent through the Full Disclosure mailing list
https://nmap.org/mailman/listinfo/fulldisclosure
Web Archives & RSS: http://seclists.org/fulldisclosure/
[prev in list] [next in list] [prev in thread] [next in thread]
Configure |
About |
News |
Add a list |
Sponsored by KoreLogic