Products: 2
Vulnerabilities: 10
Known Exploited: 0
0
Critical Level Threats
9
High Level Threats
1
Medium Level Threats
0
Low Level Threats
Vulnerabilities
100806040200
JanFebMarAprMayJunJulAugSepOctNovDec
Critical Level Threats
High Level Threats
Medium Level Threats
Low Level Threats
Products Security index
Actions
Items Per Page
Vulnerabilities
CVE-2019-9662
An issue was discovered in JTBC(PHP) 3.0.1.8. Its cache management module is flawed. An arbitrary file ending in "inc.php" can be deleted via a console/cache/manage.php?type=action&action=batch&batch=delete&ids=../ substring.
Last Modified: Nov 21, 2024
Published: Mar 11, 2019
CVE-2018-17429
/console/account/manage.php?type=action&action=add in JTBC v3.0(C) has CSRF for adding an administrator account.
Last Modified: Nov 21, 2024
Published: Mar 07, 2019
CVE-2019-8433
JTBC(PHP) 3.0.1.8 allows Arbitrary File Upload via the console/#/console/file/manage.php?type=list URI, as demonstrated by a .php file.
Last Modified: Nov 21, 2024
Published: Feb 18, 2019
CVE-2018-19547
JTBC(PHP) 3.0.1.7 has XSS via the console/xml/manage.php?type=action&action=edit content parameter.
Last Modified: Nov 21, 2024
Published: Nov 26, 2018
CVE-2018-19546
JTBC(PHP) 3.0.1.7 has CSRF via the console/xml/manage.php?type=action&action=edit URI, as demonstrated by an XSS payload in the content parameter.
Last Modified: Nov 21, 2024
Published: Nov 26, 2018
Items Per Page
