Release date:
Updated on:
Affected Systems:
BlogEngine. NET BlogEngine. NET 2.0
Description:
--------------------------------------------------------------------------------
Bugtraq id: 64635
CVE (CAN) ID: CVE-2013-6953
BlogEngine. NET is a lightweight ASP. NET blog platform.
BlogEngine. NET 2.8.0.0 and earlier versions have the information leakage vulnerability, which allows unauthenticated users to view the user names and hash passwords of BlogEngine.net sites.
<* Source: Ali Hussein
Link: http://www.kb.cert.org/vuls/id/553166
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
BlogEngine. NET
--------------
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://www.dotnetblogengine.net/