Jtbc
Jtbc PHP: vulnerabilidades y CVE
Jtbc PHP tiene 9 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE9
Últimos 12 meses0
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2019-9662 | Alta (7.5) | 1.7% | — | 11 mar 2019 | An issue was discovered in JTBC(PHP) 3.0.1.8. Its cache management module is flawed. An arbitrary file ending in "inc.php" can be deleted via a console/cache/manage.php?type=action&action=batch&batch=delete&ids=../… |
| CVE-2019-8433 | Alta (7.5) | 1.2% | — | 18 feb 2019 | JTBC(PHP) 3.0.1.8 allows Arbitrary File Upload via the console/#/console/file/manage.php?type=list URI, as demonstrated by a .php file. |
| CVE-2018-19547 | Media (6.1) | 0.73% | — | 26 nov 2018 | JTBC(PHP) 3.0.1.7 has XSS via the console/xml/manage.php?type=action&action=edit content parameter. |
| CVE-2018-19546 | Alta (8.8) | 0.54% | — | 26 nov 2018 | JTBC(PHP) 3.0.1.7 has CSRF via the console/xml/manage.php?type=action&action=edit URI, as demonstrated by an XSS payload in the content parameter. |
| CVE-2018-19327 | Alta (8.8) | 0.49% | — | 17 nov 2018 | An issue was discovered in JTBC(PHP) 3.0.1.7. aboutus/manage.php?type=action&action=add allows CSRF. |
| CVE-2018-18436 | Alta (8.8) | 0.51% | — | 17 oct 2018 | JTBC(PHP) 3.0 allows CSRF for creating an account via the console/account/manage.php?type=action&action=add URI. |
| CVE-2018-17838 | Alta (7.5) | 1.5% | — | 1 oct 2018 | An issue was discovered in JTBC(PHP) 3.0.1.6. Arbitrary file read operations are possible via a /console/#/console/file/manage.php?type=list&path=c:/ substring. |
| CVE-2018-17837 | Alta (7.5) | 1.3% | — | 1 oct 2018 | An issue was discovered in JTBC(PHP) 3.0.1.6. Arbitrary file deletion is possible via a /console/file/manage.php?type=action&action=delete&path=c%3A%2F substring. |
| CVE-2018-17836 | Alta (8.8) | 1.6% | — | 1 oct 2018 | An issue was discovered in JTBC(PHP) 3.0.1.6. It allows remote attackers to execute arbitrary PHP code by using a /console/file/manage.php?type=action&action=addfile&path=..%2F substring to upload, in conjunction with a… |