Products: 2
    Vulnerabilities: 10
    Known Exploited: 0
    0
    Critical Level Threats
    9
    High Level Threats
    1
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2019-9662

    An issue was discovered in JTBC(PHP) 3.0.1.8. Its cache management module is flawed. An arbitrary file ending in "inc.php" can be deleted via a console/cache/manage.php?type=action&action=batch&batch=delete&ids=../ substring.

    Last Modified: Nov 21, 2024
    Published: Mar 11, 2019

    CVE-2018-17429

    /console/account/manage.php?type=action&action=add in JTBC v3.0(C) has CSRF for adding an administrator account.

    Last Modified: Nov 21, 2024
    Published: Mar 07, 2019

    CVE-2019-8433

    JTBC(PHP) 3.0.1.8 allows Arbitrary File Upload via the console/#/console/file/manage.php?type=list URI, as demonstrated by a .php file.

    Last Modified: Nov 21, 2024
    Published: Feb 18, 2019

    CVE-2018-19547

    JTBC(PHP) 3.0.1.7 has XSS via the console/xml/manage.php?type=action&action=edit content parameter.

    Last Modified: Nov 21, 2024
    Published: Nov 26, 2018

    CVE-2018-19546

    JTBC(PHP) 3.0.1.7 has CSRF via the console/xml/manage.php?type=action&action=edit URI, as demonstrated by an XSS payload in the content parameter.

    Last Modified: Nov 21, 2024
    Published: Nov 26, 2018
    Items Per Page
    Jtbc Vulnerabilities & Security CVEs | CVE-DB