Nibbleblog 4.0.5

CPE Details

Nibbleblog 4.0.5
4.0.5
2019-06-25
13h11 +00:00
2019-06-25
13h11 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:nibbleblog:nibbleblog:4.0.5:*:*:*:*:*:*:*

Informations

Vendor

nibbleblog

Product

nibbleblog

Version

4.0.5

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2019-7719 2019-02-11 03h00 +00:00 Nibbleblog 4.0.5 allows eval injection by placing PHP code in the install.php username parameter and then making a content/private/shadow.php request.
9.8
Critical
CVE-2018-16604 2018-09-06 16h00 +00:00 An issue was discovered in Nibbleblog v4.0.5. With an admin's username and password, an attacker can execute arbitrary PHP code by changing the username because the username is surrounded by double quotes (e.g., "${phpinfo()}").
7.2
High
CVE-2018-6470 2018-02-01 12h00 +00:00 Nibbleblog 4.0.5 on macOS defaults to having .DS_Store in each directory, causing DS_Store information to leak.
5.3
Medium