An issue was discovered in Nibbleblog v4.0.5. With an admin's username and password, an attacker can execute arbitrary PHP code by changing the username because the username is surrounded by double quotes (e.g., "${phpinfo()}").
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://github.com/dignajar/nibbleblog/issues/131 |
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2018-09-06T16:00:00Z
Updated: 2024-09-16T23:50:42.050Z
Reserved: 2018-09-06T00:00:00Z
Link: CVE-2018-16604
Vulnrichment
No data.
NVD
Status : Modified
Published: 2018-09-06T16:29:05.453
Modified: 2024-11-21T03:53:02.753
Link: CVE-2018-16604
Redhat
No data.