MidnightBSD

Advisories for dotnetblogengine

CVE-2008-6476 MEDIUM

Cross-site scripting (XSS) vulnerability in blog/search.aspx in BlogEngine.NET allows remote attackers to inject arbitrary web script or HTML via the q parameter.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
dotnetblogengine blogengine.net *
CVE-2013-6953 MEDIUM

BlogEngine.NET 2.8.0.0 and earlier allows remote attackers to read usernames and password hashes via a request for the sioc.axd file.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
dotnetblogengine blogengine.net 2.5
dotnetblogengine blogengine.net 1.5
dotnetblogengine blogengine.net *
dotnetblogengine blogengine.net 2.0
dotnetblogengine blogengine.net 2.7
dotnetblogengine blogengine.net 2.6
dotnetblogengine blogengine.net 1.4.5
dotnetblogengine blogengine.net 1.6