BlogEngine.Net Security Exploit

This is serious business if you're running BlogEngine.net.

The exploit allows a user to use the javascript axd to access the user.xml file and display its contents in the browser.  If you're eyeballs are jittery right now you've got the right reaction unless you're just highly caffienated and don't mind username and passwords in plain text.

Danny Douglass has a quick fix by replacing the current BlogEngine.Core.dll with his updated version.  I'm running the update on this site as a proof of concept of it working.

 

Digg It!DZone It!StumbleUponTechnoratiRedditDel.icio.usNewsVineFurlBlinkList

Related posts

Add comment


(Will show your Gravatar icon)  

  Country flag

[b][/b] - [i][/i] - [u][/u]- [quote][/quote]



Live preview

August 21. 2008 12:34 PM

About Me

I'm Ian Suttle and I work for IGN Entertainment, a division of Fox Interactive Media.

Recent posts