CVE-2023-33404
- EPSS 81.44%
- Veröffentlicht 26.06.2023 20:15:10
- Zuletzt bearbeitet 21.11.2024 08:05:32
An Unrestricted Upload vulnerability, due to insufficient validation on UploadControlled.cs file, in BlogEngine.Net version 3.3.8.0 and earlier allows remote attackers to execute remote code.
CVE-2023-33405
- EPSS 36.33%
- Veröffentlicht 21.06.2023 21:15:11
- Zuletzt bearbeitet 06.12.2024 18:15:21
Blogengine.net 3.3.8.0 and earlier is vulnerable to Open Redirect.
CVE-2023-22858
- EPSS 0.08%
- Veröffentlicht 06.03.2023 07:15:12
- Zuletzt bearbeitet 21.11.2024 07:45:32
An Improper Access Control vulnerability in BlogEngine.NET 3.3.8.0, allows unauthenticated visitors to access the files of unpublished blogs.
CVE-2023-22856
- EPSS 0.11%
- Veröffentlicht 06.03.2023 07:15:11
- Zuletzt bearbeitet 21.11.2024 07:45:32
A stored Cross-site Scripting (XSS) vulnerability in BlogEngine.NET 3.3.8.0, allows injection of arbitrary JavaScript in the security context of a blog visitor through an upload of a specially crafted file.
CVE-2023-22857
- EPSS 0.11%
- Veröffentlicht 06.03.2023 07:15:11
- Zuletzt bearbeitet 21.11.2024 07:45:32
A stored Cross-site Scripting (XSS) vulnerability in BlogEngine.NET 3.3.8.0, allows injection of arbitrary JavaScript in the security context of a blog visitor through an injection of a malicious payload into a blog post.
CVE-2022-41417
- EPSS 0.34%
- Veröffentlicht 18.01.2023 14:15:10
- Zuletzt bearbeitet 03.04.2025 19:15:37
BlogEngine.NET v3.3.8.0 allows an attacker to create any folder with "files" prefix under ~/App_Data/.
CVE-2022-41418
- EPSS 1.28%
- Veröffentlicht 19.12.2022 20:15:11
- Zuletzt bearbeitet 17.04.2025 15:15:47
An issue in the component BlogEngine/BlogEngine.NET/AppCode/Api/UploadController.cs of BlogEngine.NET v3.3.8.0 allows attackers to execute arbitrary code via uploading a crafted PNG file.
CVE-2022-36600
- EPSS 0.26%
- Veröffentlicht 02.09.2022 05:15:07
- Zuletzt bearbeitet 21.11.2024 07:13:22
BlogEngine v3.3.8.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /blogengine/api/posts. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Desc...
CVE-2022-28921
- EPSS 0.2%
- Veröffentlicht 18.05.2022 18:15:10
- Zuletzt bearbeitet 21.11.2024 06:58:11
A Cross-Site Request Forgery (CSRF) vulnerability discovered in BlogEngine.Net v3.3.8.0 allows unauthenticated attackers to read arbitrary files on the hosting web server.
CVE-2022-25591
- EPSS 9.74%
- Veröffentlicht 13.05.2022 15:15:08
- Zuletzt bearbeitet 21.11.2024 06:52:24
BlogEngine.NET v3.3.8.0 was discovered to contain an arbitrary file deletion vulnerability which allows attackers to delete files within the web server root directory via a crafted HTTP request.