CVE-2018-7736: XSS
Published Mar 6, 2018
·Updated
DISPUTED In Z-BlogPHP 1.5.1.1740, cmd.php has XSS via the ZCBLOGSUBNAME parameter or ZCUPLOADFILETYPE parameter. NOTE: the software maintainer disputes that this is a vulnerability.
Affected Software
1 affected component
ZblogCN Z-blogphp=1.5.1.1740
Event History
Mar 6, 2018
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Disputed
09:29 PM
Data Sourced
via NVD·09:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for Z-BlogPHP?
The vulnerability ID for Z-BlogPHP is CVE-2018-7736.
2
What is the severity of CVE-2018-7736?
The severity of CVE-2018-7736 is medium with a CVSS score of 6.1.
3
How does the vulnerability occur in Z-BlogPHP?
The vulnerability in Z-BlogPHP occurs in the cmd.php file through the ZC_BLOG_SUBNAME parameter or ZC_UPLOAD_FILETYPE parameter, leading to XSS (Cross-Site Scripting) attacks.
4
What version of Z-BlogPHP is affected by CVE-2018-7736?
The version 1.5.1.1740 of Z-BlogPHP is affected by CVE-2018-7736.
5
Is CVE-2018-7736 a disputed vulnerability?
Yes, CVE-2018-7736 is a disputed vulnerability according to the software maintainer.