BlogEngine.NET 3.3.7.0 allows /api/filemanager Directory Traversal via the path parameter.
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
Link | Tags |
---|---|
https://github.com/rxtur/BlogEngine.NET/commits/master | third party advisory patch |
http://seclists.org/fulldisclosure/2019/Jun/44 | third party advisory mailing list |
https://www.securitymetrics.com/blog/Blogenginenet-Directory-Traversal-Listing-Login-Page-Unvalidated-Redirect | exploit third party advisory patch |