VYPR

Zblogphp

by Zblogcn

Source repositories

CVEs (24)

  • CVE-2018-7737MedMar 6, 2018
    risk 0.31cvss 5.3epss 0.08

    In Z-BlogPHP 1.5.1.1740, there is Web Site physical path leakage, as demonstrated by admin_footer.php or admin_footer.php. NOTE: the software maintainer disputes that this is a vulnerability

  • CVE-2018-19556MedNov 26, 2018
    risk 0.28cvss 4.3epss 0.01

    zb_system/admin/index.php?act=UploadMng in Z-BlogPHP 1.5 mishandles file preview, leading to content spoofing. NOTE: the software maintainer disputes that this is a vulnerability

  • CVE-2020-23352HigJan 27, 2021
    risk 0.00cvss 7.5epss 0.01

    Z-BlogPHP 1.6.0 Valyria is affected by incorrect access control. PHP loose comparison and a magic hash can be used to bypass authentication. zb_user/plugin/passwordvisit/include.php:passwordvisit_input_password() uses loose comparison to authenticate, which can be bypassed via…

  • CVE-2018-6656MedFeb 6, 2018
    risk 0.00cvss 6.5epss 0.01

    Z-BlogPHP 1.5.1 has CSRF via zb_users/plugin/AppCentre/app_del.php, as demonstrated by deleting files and directories.

Page 2 of 2