First published: Thu Nov 22 2018(Updated: )
** DISPUTED ** zb_system/function/lib/upload.php in Z-BlogPHP through 1.5.1 allows remote attackers to execute arbitrary PHP code by using the image/jpeg content type in an upload to the zb_system/admin/index.php?act=UploadMng URI. NOTE: The vendor's position is "We have no dynamic including. No one can run PHP by uploading an image in current version." It also requires authentication.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zblogcn Z-blogphp | <=1.5.1 | |
<=1.5.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2018-19463.
The title of this vulnerability is ** DISPUTED ** zb_system/function/lib/upload.php in Z-BlogPHP through 1.5.1 allows remote attackers …
The severity of CVE-2018-19463 is high with a CVSS score of 8.8.
CVE-2018-19463 allows remote attackers to execute arbitrary PHP code.
To fix CVE-2018-19463, apply the necessary patches or updates provided by the vendor Z-BlogPHP.