VYPR

Jtbc

by Jtbc

CVEs (7)

  • CVE-2018-17836HigOct 1, 2018
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered in JTBC(PHP) 3.0.1.6. It allows remote attackers to execute arbitrary PHP code by using a /console/file/manage.php?type=action&action=addfile&path=..%2F substring to upload, in conjunction with a multipart/form-data PHP payload.

  • CVE-2018-17837HigOct 1, 2018
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in JTBC(PHP) 3.0.1.6. Arbitrary file deletion is possible via a /console/file/manage.php?type=action&action=delete&path=c%3A%2F substring.

  • CVE-2019-9662Mar 11, 2019
    risk 0.00cvss epss 0.02

    An issue was discovered in JTBC(PHP) 3.0.1.8. Its cache management module is flawed. An arbitrary file ending in "inc.php" can be deleted via a console/cache/manage.php?type=action&action=batch&batch=delete&ids=../ substring.

  • CVE-2018-17429Mar 7, 2019
    risk 0.00cvss epss 0.01

    /console/account/manage.php?type=action&action=add in JTBC v3.0(C) has CSRF for adding an administrator account.

  • CVE-2019-8433Feb 18, 2019
    risk 0.00cvss epss 0.01

    JTBC(PHP) 3.0.1.8 allows Arbitrary File Upload via the console/#/console/file/manage.php?type=list URI, as demonstrated by a .php file.

  • CVE-2018-19547Nov 26, 2018
    risk 0.00cvss epss 0.01

    JTBC(PHP) 3.0.1.7 has XSS via the console/xml/manage.php?type=action&action=edit content parameter.

  • CVE-2018-18436Oct 17, 2018
    risk 0.00cvss epss 0.01

    JTBC(PHP) 3.0 allows CSRF for creating an account via the console/account/manage.php?type=action&action=add URI.