Show filters
3 Total Results
Displaying 1-3 of 3
Sort by:
Attacker Value
Unknown
CVE-2018-17838
Disclosure Date: October 01, 2018 (last updated November 27, 2024)
An issue was discovered in JTBC(PHP) 3.0.1.6. Arbitrary file read operations are possible via a /console/#/console/file/manage.php?type=list&path=c:/ substring.
0
Attacker Value
Unknown
CVE-2018-17836
Disclosure Date: October 01, 2018 (last updated November 27, 2024)
An issue was discovered in JTBC(PHP) 3.0.1.6. It allows remote attackers to execute arbitrary PHP code by using a /console/file/manage.php?type=action&action=addfile&path=..%2F substring to upload, in conjunction with a multipart/form-data PHP payload.
0
Attacker Value
Unknown
CVE-2018-17837
Disclosure Date: October 01, 2018 (last updated November 27, 2024)
An issue was discovered in JTBC(PHP) 3.0.1.6. Arbitrary file deletion is possible via a /console/file/manage.php?type=action&action=delete&path=c%3A%2F substring.
0