CVE-2018-9153: Malicious File Upload
The plugin upload component in Z-BlogPHP 1.5.1 allows remote attackers to execute arbitrary PHP code via the appid parameter to zbusers/plugin/AppCentre/pluginedit.php because of an unanchored regular expression, a different vulnerability than CVE-2018-8893. The component must be accessed directly by an administrator, or through CSRF.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-9153?
CVE-2018-9153 is a vulnerability in Z-BlogPHP 1.5.1 that allows remote attackers to execute arbitrary PHP code.
How does CVE-2018-9153 work?
CVE-2018-9153 works by exploiting the plugin upload component in Z-BlogPHP 1.5.1 through the app_id parameter to zb_users/plugin/AppCentre/plugin_edit.php.
What is the severity of CVE-2018-9153?
The severity of CVE-2018-9153 is high with a severity value of 7.2.
Which software versions are affected by CVE-2018-9153?
Z-BlogPHP 1.5.1 is affected by CVE-2018-9153.
How can I fix CVE-2018-9153?
To fix CVE-2018-9153, update to a version of Z-BlogPHP that is not affected by the vulnerability.