Show filters
7 Total Results
Displaying 1-7 of 7
Sort by:
Attacker Value
Unknown
CVE-2018-9169
Disclosure Date: April 16, 2018 (last updated November 26, 2024)
Z-BlogPHP 1.5.1 has XSS via the zb_users/plugin/AppCentre/plugin_edit.php app_id parameter. The component must be accessed directly by an administrator, or through CSRF.
0
Attacker Value
Unknown
CVE-2018-9153
Disclosure Date: April 16, 2018 (last updated November 26, 2024)
The plugin upload component in Z-BlogPHP 1.5.1 allows remote attackers to execute arbitrary PHP code via the app_id parameter to zb_users/plugin/AppCentre/plugin_edit.php because of an unanchored regular expression, a different vulnerability than CVE-2018-8893. The component must be accessed directly by an administrator, or through CSRF.
0
Attacker Value
Unknown
CVE-2018-8893
Disclosure Date: March 31, 2018 (last updated November 26, 2024)
Z-BlogPHP 1.5.1 Zero has CSRF in plugin_edit.php, resulting in the ability to execute arbitrary PHP code.
0
Attacker Value
Unknown
CVE-2018-7736
Disclosure Date: March 06, 2018 (last updated November 08, 2023)
In Z-BlogPHP 1.5.1.1740, cmd.php has XSS via the ZC_BLOG_SUBNAME parameter or ZC_UPLOAD_FILETYPE parameter. NOTE: the software maintainer disputes that this is a vulnerability
0
Attacker Value
Unknown
CVE-2018-7737
Disclosure Date: March 06, 2018 (last updated November 08, 2023)
In Z-BlogPHP 1.5.1.1740, there is Web Site physical path leakage, as demonstrated by admin_footer.php or admin_footer.php. NOTE: the software maintainer disputes that this is a vulnerability
0
Attacker Value
Unknown
CVE-2018-6846
Disclosure Date: February 08, 2018 (last updated November 26, 2024)
Z-BlogPHP 1.5.1 allows remote attackers to discover the full path via a direct request to zb_system/function/lib/upload.php.
0
Attacker Value
Unknown
CVE-2018-6656
Disclosure Date: February 06, 2018 (last updated November 26, 2024)
Z-BlogPHP 1.5.1 has CSRF via zb_users/plugin/AppCentre/app_del.php, as demonstrated by deleting files and directories.
0