Логотип exploitDog
bind:CVE-2018-11208
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2018-11208

Количество 2

Количество 2

nvd логотип

CVE-2018-11208

больше 7 лет назад

An issue was discovered in Z-BlogPHP 2.0.0. There is a persistent XSS that allows remote attackers to inject arbitrary web script or HTML into background web site settings via the "copyright information office" field. NOTE: the vendor indicates that the product was not intended to block this type of XSS by a user with the admin privilege

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-gm9r-74vm-63jm

больше 3 лет назад

** DISPUTED ** An issue was discovered in Z-BlogPHP 2.0.0. There is a persistent XSS that allows remote attackers to inject arbitrary web script or HTML into background web site settings via the "copyright information office" field. NOTE: the vendor indicates that the product was not intended to block this type of XSS by a user with the admin privilege.

CVSS3: 4.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2018-11208

An issue was discovered in Z-BlogPHP 2.0.0. There is a persistent XSS that allows remote attackers to inject arbitrary web script or HTML into background web site settings via the "copyright information office" field. NOTE: the vendor indicates that the product was not intended to block this type of XSS by a user with the admin privilege

CVSS3: 4.8
0%
Низкий
больше 7 лет назад
github логотип
GHSA-gm9r-74vm-63jm

** DISPUTED ** An issue was discovered in Z-BlogPHP 2.0.0. There is a persistent XSS that allows remote attackers to inject arbitrary web script or HTML into background web site settings via the "copyright information office" field. NOTE: the vendor indicates that the product was not intended to block this type of XSS by a user with the admin privilege.

CVSS3: 4.8
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу