Known Vulnerabilities for products from Jtbc
Listed below are 10 of the newest known vulnerabilities associated with the vendor "Jtbc".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2019-9662 json | An issue was discovered in JTBC(PHP) 3.0.1.8. Its cache management module is flawed. An arbitrary file ending in "inc.php" ca... | 7.5 - HIGH | 2019-03-11 | 2020-08-24 |
| CVE-2019-8433 json | JTBC(PHP) 3.0.1.8 allows Arbitrary File Upload via the console/#/console/file/manage.php?type=list URI, as demonstrated by a ... | 7.5 - HIGH | 2019-02-18 | 2019-02-20 |
| CVE-2018-19547 json | JTBC(PHP) 3.0.1.7 has XSS via the console/xml/manage.php?type=action&action=edit content parameter. | 6.1 - MEDIUM | 2018-11-26 | 2018-12-19 |
| CVE-2018-19546 json | JTBC(PHP) 3.0.1.7 has CSRF via the console/xml/manage.php?type=action&action=edit URI, as demonstrated by an XSS payload in t... | 8.8 - HIGH | 2018-11-26 | 2020-08-24 |
| CVE-2018-19327 json | An issue was discovered in JTBC(PHP) 3.0.1.7. aboutus/manage.php?type=action&action=add allows CSRF. | 8.8 - HIGH | 2018-11-17 | 2018-12-18 |
| CVE-2018-18436 json | JTBC(PHP) 3.0 allows CSRF for creating an account via the console/account/manage.php?type=action&action=add URI. | 8.8 - HIGH | 2018-10-17 | 2020-06-17 |
| CVE-2018-17838 json | An issue was discovered in JTBC(PHP) 3.0.1.6. Arbitrary file read operations are possible via a /console/#/console/file/manag... | 7.5 - HIGH | 2018-10-01 | 2018-11-28 |
| CVE-2018-17837 json | An issue was discovered in JTBC(PHP) 3.0.1.6. Arbitrary file deletion is possible via a /console/file/manage.php?type=action&... | 7.5 - HIGH | 2018-10-01 | 2020-08-24 |
| CVE-2018-17836 json | An issue was discovered in JTBC(PHP) 3.0.1.6. It allows remote attackers to execute arbitrary PHP code by using a /console/fi... | 8.8 - HIGH | 2018-10-01 | 2020-08-24 |
| CVE-2018-17429 json | /console/account/manage.php?type=action&action=add in JTBC v3.0(C) has CSRF for adding an administrator account. | 8.8 - HIGH | 2019-03-07 | 2019-03-08 |