BlogEngine.NET 3.3 permette attacchi xx tramite il corpo POST a metaweblog.axd. |
http://packetstormsecurity.com/files/151063/BlogEngine-3.3-XML-External-Entity-Injection.html https://github.com/rxtur/BlogEngine.NET/commits/master https://www.exploit-db.com/exploits/46106/ https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-14485 |
Vulnerabilità: CVE-2018-14485
