CVE-2013-6953

Severity CVSS v4.0:
Pending analysis
Type:
CWE-200 Information Leak / Disclosure
Publication date:
03/01/2014
Last modified:
11/04/2025

Description

BlogEngine.NET 2.8.0.0 and earlier allows remote attackers to read usernames and password hashes via a request for the sioc.axd file.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:dotnetblogengine:blogengine.net:*:*:*:*:*:*:*:* 2.8 (including)
cpe:2.3:a:dotnetblogengine:blogengine.net:1.4.5:*:*:*:*:*:*:*
cpe:2.3:a:dotnetblogengine:blogengine.net:1.5:*:*:*:*:*:*:*
cpe:2.3:a:dotnetblogengine:blogengine.net:1.6:*:*:*:*:*:*:*
cpe:2.3:a:dotnetblogengine:blogengine.net:2.0:*:*:*:*:*:*:*
cpe:2.3:a:dotnetblogengine:blogengine.net:2.5:*:*:*:*:*:*:*
cpe:2.3:a:dotnetblogengine:blogengine.net:2.6:*:*:*:*:*:*:*
cpe:2.3:a:dotnetblogengine:blogengine.net:2.7:*:*:*:*:*:*:*