Vulnerabilities > Zblogcn > Medium

DATE CVE VULNERABILITY TITLE RISK
2018-02-08 CVE-2018-6846 Information Exposure vulnerability in Zblogcn Z-Blogphp 1.5.1
Z-BlogPHP 1.5.1 allows remote attackers to discover the full path via a direct request to zb_system/function/lib/upload.php.
network
low complexity
zblogcn CWE-200
5.3
2018-02-06 CVE-2018-6656 Cross-Site Request Forgery (CSRF) vulnerability in Zblogcn Z-Blogphp 1.5.1
Z-BlogPHP 1.5.1 has CSRF via zb_users/plugin/AppCentre/app_del.php, as demonstrated by deleting files and directories.
network
low complexity
zblogcn CWE-352
6.5