Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
nibbleblog nibbleblog 4.0.5 vulnerabilities and exploits
(subscribe to this query)
7.5
CVSSv2
CVE-2019-7719
Nibbleblog 4.0.5 allows eval injection by placing PHP code in the install.php username parameter and then making a content/private/shadow.php request.
Nibbleblog Nibbleblog 4.0.5
6.8
CVSSv2
CVE-2015-6966
Multiple cross-site request forgery (CSRF) vulnerabilities in Nibbleblog prior to 4.0.5 allow remote malicious users to hijack the authentication of administrators for requests that (1) create a post via a new_simple action to admin.php or (2) conduct cross-site scripting (XSS) a...
Nibbleblog Nibbleblog
6.5
CVSSv2
CVE-2018-16604
An issue exists in Nibbleblog v4.0.5. With an admin's username and password, an attacker can execute arbitrary PHP code by changing the username because the username is surrounded by double quotes (e.g., "${phpinfo()}").
Nibbleblog Nibbleblog 4.0.5
6.5
CVSSv2
CVE-2015-6967
Unrestricted file upload vulnerability in the My Image plugin in Nibbleblog prior to 4.0.5 allows remote administrators to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in content/private/plugins/my_ima...
Nibbleblog Nibbleblog
1 EDB exploit
7 Github repositories
5
CVSSv2
CVE-2018-6470
Nibbleblog 4.0.5 on macOS defaults to having .DS_Store in each directory, causing DS_Store information to leak.
Nibbleblog Nibbleblog 4.0.5
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
camera
bypass
CVE-2024-3592
CVE-2024-37383
CVE-2024-24919
CVE-2024-27822
CVE-2024-36788
CVE-2024-36789
man-in-the-middle
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started