VYPR

Zblogphp

by Zblogcn

Source repositories

CVEs (24)

  • CVE-2018-11208MedMay 16, 2018
    risk 0.31cvss 4.8epss 0.01

    An issue was discovered in Z-BlogPHP 2.0.0. There is a persistent XSS that allows remote attackers to inject arbitrary web script or HTML into background web site settings via the "copyright information office" field. NOTE: the vendor indicates that the product was not intended…

  • CVE-2018-9169MedApr 16, 2018
    risk 0.31cvss 4.8epss 0.01

    Z-BlogPHP 1.5.1 has XSS via the zb_users/plugin/AppCentre/plugin_edit.php app_id parameter. The component must be accessed directly by an administrator, or through CSRF.

  • CVE-2018-7737MedMar 6, 2018
    risk 0.31cvss 5.3epss 0.08

    In Z-BlogPHP 1.5.1.1740, there is Web Site physical path leakage, as demonstrated by admin_footer.php or admin_footer.php. NOTE: the software maintainer disputes that this is a vulnerability

  • CVE-2018-19556MedNov 26, 2018
    risk 0.28cvss 4.3epss 0.01

    zb_system/admin/index.php?act=UploadMng in Z-BlogPHP 1.5 mishandles file preview, leading to content spoofing. NOTE: the software maintainer disputes that this is a vulnerability

Page 2 of 2