CVE-2018-6846: Infoleak
Published Feb 8, 2018
·Updated
Z-BlogPHP 1.5.1 allows remote attackers to discover the full path via a direct request to zbsystem/function/lib/upload.php.
Affected Software
1 affected component
ZblogCN Z-blogphp=1.5.1
Event History
Feb 8, 2018
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Data Sourced
via NVD·04:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this security issue?
The vulnerability ID of this security issue is CVE-2018-6846.
2
What is the title of this security vulnerability?
The title of this security vulnerability is 'Z-BlogPHP 1.5.1 allows remote attackers to discover the full path via a direct request to zb_system/…'.
3
What is the affected software?
The affected software is Z-BlogPHP version 1.5.1.
4
What is the severity of this vulnerability?
The severity of this vulnerability is medium with a CVSS score of 5.3.
5
How can I fix this vulnerability?
A fix for this vulnerability is not available yet. Follow the reference link for updates on this issue.