6.5
CVSSv2

CVE-2018-19463

Published: 22/11/2018 Updated: 11/04/2024
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 578
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

zb_system/function/lib/upload.php in Z-BlogPHP up to and including 1.5.1 allows remote malicious users to execute arbitrary PHP code by using the image/jpeg content type in an upload to the zb_system/admin/index.php?act=UploadMng URI. NOTE: The vendor's position is "We have no dynamic including. No one can run PHP by uploading an image in current version." It also requires authentication

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

zblogcn z-blogphp