5
CVSSv2

CVE-2018-6029

Published: 23/01/2018 Updated: 12/02/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The copy function in application/admin/controller/Article.php in NoneCms 1.3.0 allows remote malicious users to access the content of internal and external network resources via Server Side Request Forgery (SSRF), because URL validation only considers whether the URL contains the "csdn" substring.

Vulnerable Product Search on Vulmon Subscribe to Product

5none nonecms 1.3.0