Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The plugin upload component in Z-BlogPHP 1.5.1 allows remote attackers to execute arbitrary PHP code via the app_id parameter to zb_users/plugin/AppCentre/plugin_edit.php because of an unanchored regular expression, a different vulnerability than CVE-2018-8893. The component must be accessed directly by an administrator, or through CSRF.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Z-BlogPHP plugin upload组件安全漏洞
Vulnerability Description
Z-BlogPHP是由Z-Blog社区开发的一套开源的基于PHP的博客系统。plugin upload component是其中的一个插件上传组件。 Z-BlogPHP 1.5.1版本中的plugin upload组件存在安全漏洞。远程攻击者可通过向zb_users/plugin/AppCentre/plugin_edit.php文件发送‘app_id’参数利用该漏洞执行任意PHP代码。
CVSS Information
N/A
Vulnerability Type
N/A