CVE-2019-9662
- EPSS 0.33%
- Veröffentlicht 11.03.2019 05:29:00
- Zuletzt bearbeitet 21.11.2024 04:52:04
An issue was discovered in JTBC(PHP) 3.0.1.8. Its cache management module is flawed. An arbitrary file ending in "inc.php" can be deleted via a console/cache/manage.php?type=action&action=batch&batch=delete&ids=../ substring.
CVE-2019-8433
- EPSS 0.24%
- Veröffentlicht 18.02.2019 00:29:00
- Zuletzt bearbeitet 21.11.2024 04:49:53
JTBC(PHP) 3.0.1.8 allows Arbitrary File Upload via the console/#/console/file/manage.php?type=list URI, as demonstrated by a .php file.
CVE-2018-19546
- EPSS 0.15%
- Veröffentlicht 26.11.2018 07:29:00
- Zuletzt bearbeitet 21.11.2024 03:58:08
JTBC(PHP) 3.0.1.7 has CSRF via the console/xml/manage.php?type=action&action=edit URI, as demonstrated by an XSS payload in the content parameter.
CVE-2018-19547
- EPSS 0.24%
- Veröffentlicht 26.11.2018 07:29:00
- Zuletzt bearbeitet 21.11.2024 03:58:08
JTBC(PHP) 3.0.1.7 has XSS via the console/xml/manage.php?type=action&action=edit content parameter.
CVE-2018-19327
- EPSS 0.15%
- Veröffentlicht 17.11.2018 15:29:00
- Zuletzt bearbeitet 21.11.2024 03:57:43
An issue was discovered in JTBC(PHP) 3.0.1.7. aboutus/manage.php?type=action&action=add allows CSRF.
CVE-2018-18436
- EPSS 0.14%
- Veröffentlicht 17.10.2018 06:29:00
- Zuletzt bearbeitet 21.11.2024 03:55:55
JTBC(PHP) 3.0 allows CSRF for creating an account via the console/account/manage.php?type=action&action=add URI.
CVE-2018-17836
- EPSS 1.19%
- Veröffentlicht 01.10.2018 08:29:01
- Zuletzt bearbeitet 21.11.2024 03:55:01
An issue was discovered in JTBC(PHP) 3.0.1.6. It allows remote attackers to execute arbitrary PHP code by using a /console/file/manage.php?type=action&action=addfile&path=..%2F substring to upload, in conjunction with a multipart/form-data PHP payloa...
CVE-2018-17837
- EPSS 0.52%
- Veröffentlicht 01.10.2018 08:29:01
- Zuletzt bearbeitet 21.11.2024 03:55:01
An issue was discovered in JTBC(PHP) 3.0.1.6. Arbitrary file deletion is possible via a /console/file/manage.php?type=action&action=delete&path=c%3A%2F substring.
CVE-2018-17838
- EPSS 0.42%
- Veröffentlicht 01.10.2018 08:29:01
- Zuletzt bearbeitet 21.11.2024 03:55:01
An issue was discovered in JTBC(PHP) 3.0.1.6. Arbitrary file read operations are possible via a /console/#/console/file/manage.php?type=list&path=c:/ substring.