VendorsJTBCjtbc_php3.0.1.8
Vulnerabilities

JTBC PHP 3.0.1.8

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2019-9662
An issue was discovered in JTBC(PHP) 3.0.1.8. Its cache management module is flawed. An arbitrary file ending in "inc.php" can be deleted via a console/cache/manage.php?type=action&action=batch&batch=delete&ids=../ substring.
Published 2019-03-11 · Modified
7.5EPSS 0.017
CVE-2019-8433
JTBC(PHP) 3.0.1.8 allows Arbitrary File Upload via the console/#/console/file/manage.php?type=list URI, as demonstrated by a .php file.
Published 2019-02-18 · Modified
7.5EPSS 0.012