Identifier
|
Related Record |
Severity
|
Date Published
|
Description | Versions Affected |
---|---|---|---|---|---|
CVE-2019-7719 | Critical | Feb 11, 2019 | Nibbleblog 4.0.5 allows eval injection by placing PHP code in the install.php username parameter and then making a content/private/shadow.php request. |
v4.0.5
|
|
CVE-2018-6470 | Medium | Feb 01, 2018 | Nibbleblog 4.0.5 on macOS defaults to having .DS_Store in each directory, causing DS_Store information to leak. |
v4.0.5
|
|
CVE-2018-16604 | BDSA-2018-3121 | High | Sep 06, 2018 | An issue was discovered in Nibbleblog v4.0.5. With an admin's username and password, an attacker can execute arbitrary PHP code by changing the usernam more... |
v4.0.5
|