Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
nibbleblog nibbleblog 4.0.5 vulnerabilities and exploits
(subscribe to this query)
9.8
CVSSv3
CVE-2019-7719
Nibbleblog 4.0.5 allows eval injection by placing PHP code in the install.php username parameter and then making a content/private/shadow.php request.
Nibbleblog Nibbleblog 4.0.5
7.2
CVSSv3
CVE-2018-16604
An issue exists in Nibbleblog v4.0.5. With an admin's username and password, an attacker can execute arbitrary PHP code by changing the username because the username is surrounded by double quotes (e.g., "${phpinfo()}").
Nibbleblog Nibbleblog 4.0.5
5.3
CVSSv3
CVE-2018-6470
Nibbleblog 4.0.5 on macOS defaults to having .DS_Store in each directory, causing DS_Store information to leak.
Nibbleblog Nibbleblog 4.0.5
NA
CVE-2015-6966
Multiple cross-site request forgery (CSRF) vulnerabilities in Nibbleblog prior to 4.0.5 allow remote malicious users to hijack the authentication of administrators for requests that (1) create a post via a new_simple action to admin.php or (2) conduct cross-site scripting (XSS) a...
Nibbleblog Nibbleblog
NA
CVE-2015-6967
Unrestricted file upload vulnerability in the My Image plugin in Nibbleblog prior to 4.0.5 allows remote administrators to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in content/private/plugins/my_ima...
Nibbleblog Nibbleblog
1 EDB exploit
7 Github repositories
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
authentication bypass
CVE-2024-30051
remote
CVE-2024-27954
CVE-2023-51483
CVE-2023-47782
SSRF
CVE-2024-24715
CVE-2023-52424
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started