Vulnerability Details CVE-2020-18268
Open Redirect in Z-BlogPHP v1.5.2 and earlier allows remote attackers to obtain sensitive information via the "redirect" parameter in the component "zb_system/cmd.php."
Exploit prediction scoring system (EPSS) score
EPSS Score 0.07
EPSS Ranking 91.0%
CVSS Severity
CVSS v3 Score 6.1
CVSS v2 Score 5.8
Products affected by CVE-2020-18268
-
cpe:2.3:a:zblogcn:z-blogphp:1.5
-
cpe:2.3:a:zblogcn:z-blogphp:1.5.0.1525
-
cpe:2.3:a:zblogcn:z-blogphp:1.5.0.1525-2
-
cpe:2.3:a:zblogcn:z-blogphp:1.5.0.1525-3
-
cpe:2.3:a:zblogcn:z-blogphp:1.5.0.1525-4
-
cpe:2.3:a:zblogcn:z-blogphp:1.5.0.1525-5
-
cpe:2.3:a:zblogcn:z-blogphp:1.5.0.1525-6
-
cpe:2.3:a:zblogcn:z-blogphp:1.5.0.1525-7
-
cpe:2.3:a:zblogcn:z-blogphp:1.5.0.1525-8
-
cpe:2.3:a:zblogcn:z-blogphp:1.5.0.1626
-
cpe:2.3:a:zblogcn:z-blogphp:1.5.1
-
cpe:2.3:a:zblogcn:z-blogphp:1.5.1.1740
-
cpe:2.3:a:zblogcn:z-blogphp:1.5.2