<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>ASP.NET on Insinuator.net - Bold Statements</title>
    <link>https://insinuator.net/tags/asp.net/</link>
    <description>Recent content in ASP.NET on Insinuator.net - Bold Statements</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Mon, 08 Oct 2018 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://insinuator.net/tags/asp.net/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Vulnerabilities in Sitefinity WCMS – A Success Story of a Responsible Disclosure Process</title>
      <link>https://insinuator.net/2018/10/vulnerabilities-in-sitefinity-wcms-a-success-story-of-a-responsible-disclosure-process/</link>
      <pubDate>Mon, 08 Oct 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/10/vulnerabilities-in-sitefinity-wcms-a-success-story-of-a-responsible-disclosure-process/</guid>
      <description>&lt;h1 id=&#34;preface&#34;&gt;Preface&lt;/h1&gt;&#xA;&lt;p&gt;For those who never heard of &lt;em&gt;Sitefinity&lt;/em&gt; before, it is an &lt;em&gt;ASP.NET&lt;/em&gt;-based Web Content Management System (&lt;em&gt;WCMS&lt;/em&gt;), which is used to deploy and manage applications as other &lt;em&gt;CMS&lt;/em&gt;‘s do. A bitter quick glance at &lt;em&gt;Sitefinity&lt;/em&gt; and its advantages can be found in this &lt;a href=&#34;https://www.progress.com/documentation/sitefinity-cms/sitefinity-overview&#34;&gt;overview.&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;Delving into the core of this blog post, recently I had the opportunity to look at &lt;em&gt;Sitefinity WCMS&lt;/em&gt; in which I found two &lt;em&gt;reflected&lt;/em&gt; &lt;em&gt;Cross Site Scripting&lt;/em&gt; (&lt;em&gt;XSS&lt;/em&gt;) (&lt;em&gt;&lt;a href=&#34;https://www.cvedetails.com/cve/CVE-2018-17053/&#34; title=&#34;CVE-2018-17053 security vulnerability details&#34;&gt;CVE-2018-17053&lt;/a&gt; and &lt;a href=&#34;https://www.cvedetails.com/cve/CVE-2018-17056/&#34; title=&#34;CVE-2018-17056 security vulnerability details&#34;&gt;CVE-2018-17056&lt;/a&gt;&lt;/em&gt;), a* stored XSS* (&lt;em&gt;&lt;a href=&#34;https://www.cvedetails.com/cve/CVE-2018-17054/&#34; title=&#34;CVE-2018-17054 security vulnerability details&#34;&gt;CVE-2018-17054&lt;/a&gt;&lt;/em&gt;) and an arbitrary file upload (&lt;a href=&#34;https://www.cvedetails.com/cve/CVE-2018-17055/&#34; title=&#34;CVE-2018-17055 security vulnerability details&#34;&gt;&lt;em&gt;CVE-2018-17055&lt;/em&gt;&lt;/a&gt;) vulnerabilities.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
