VendorsZblogcnz-blogphp1.5.1
Vulnerabilities

Zblogcn Z-BlogPHP 1.5.1

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2018-8893
Z-BlogPHP 1.5.1 Zero has CSRF in plugin_edit.php, resulting in the ability to execute arbitrary PHP code.
Published 2018-03-31 · Modified
8.8EPSS 0.004
CVE-2018-9153
The plugin upload component in Z-BlogPHP 1.5.1 allows remote attackers to execute arbitrary PHP code via the app_id parameter to zb_users/plugin/AppCentre/plugin_edit.php because of an unanchored regular expression, a different vulnerability than CVE-2018-8893. The component must be accessed directly by an administrator, or through CSRF.
Published 2018-04-15 · Modified
7.2EPSS 0.012
CVE-2018-6656
Z-BlogPHP 1.5.1 has CSRF via zb_users/plugin/AppCentre/app_del.php, as demonstrated by deleting files and directories.
Published 2018-02-06 · Modified
6.5EPSS 0.005
CVE-2018-6846
Z-BlogPHP 1.5.1 allows remote attackers to discover the full path via a direct request to zb_system/function/lib/upload.php.
Published 2018-02-08 · Modified
5.3EPSS 0.014
CVE-2018-9169
Z-BlogPHP 1.5.1 has XSS via the zb_users/plugin/AppCentre/plugin_edit.php app_id parameter. The component must be accessed directly by an administrator, or through CSRF.
Published 2018-04-15 · Modified
4.8EPSS 0.005