CVE-2018-18753

Severity CVSS v4.0:
Pending analysis
Type:
CWE-918 Server-Side Request Forgery (SSRF)
Publication date:
29/10/2018
Last modified:
28/01/2019

Description

Typecho V1.1 allows remote attackers to send shell commands via base64-encoded serialized data, as demonstrated by SSRF.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:typecho:typecho:1.1:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools