VYPR

blog

by Tianchoy

CVEs (4)

  • CVE-2017-14346CriSep 12, 2017
    risk 0.64cvss 9.8epss 0.02

    upload.php in tianchoy/blog through 2017-09-12 allows unrestricted file upload and PHP code execution by using the image/jpeg, image/pjpeg, image/png, or image/gif content type for a .php file.

  • CVE-2017-14345CriSep 12, 2017
    risk 0.64cvss 9.8epss 0.01

    SQL Injection exists in tianchoy/blog through 2017-09-12 via the id parameter to view.php.

  • CVE-2023-43381HigSep 27, 2023
    risk 0.49cvss 7.5epss 0.01

    SQL Injection vulnerability in Tianchoy Blog v.1.8.8 allows a remote attacker to obtain sensitive information via the id parameter in the login.php

  • CVE-2024-7114MedJul 26, 2024
    risk 0.41cvss 6.3epss 0.01

    A vulnerability was found in Tianchoy Blog up to 1.8.8. It has been classified as critical. This affects an unknown part of the file /so.php. The manipulation of the argument search leads to sql injection. It is possible to initiate the attack remotely. The exploit has been…