Vulnerabilities > CVE-2018-14485 - XXE vulnerability in Blogengine Blogengine.Net 3.3

047910
CVSS 9.8 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
blogengine
CWE-611
critical
exploit available

Summary

BlogEngine.NET 3.3 allows XXE attacks via the POST body to metaweblog.axd.

Vulnerable Configurations

Part Description Count
Application
Blogengine
1

Exploit-Db

idEDB-ID:46106
last seen2019-01-09
modified2019-01-09
published2019-01-09
reporterExploit-DB
sourcehttps://www.exploit-db.com/download/46106
titleBlogEngine 3.3 - XML External Entity Injection

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/151063/NS-18-045.txt
idPACKETSTORM:151063
last seen2019-01-09
published2019-01-09
reporterMustafa Yalcin
sourcehttps://packetstormsecurity.com/files/151063/BlogEngine-3.3-XML-External-Entity-Injection.html
titleBlogEngine 3.3 XML External Entity Injection