CVE-2019-6034

Severity CVSS v4.0:
Pending analysis
Type:
CWE-74 Injection
Publication date:
26/12/2019
Last modified:
08/01/2020

Description

a-blog cms versions prior to Ver.2.10.23 (Ver.2.10.x), Ver.2.9.26 (Ver.2.9.x), and Ver.2.8.64 (Ver.2.8.x) allows arbitrary scripts to be executed in the context of the application due to unspecified vectors.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:appleple:a-blog_cms:*:*:*:*:*:*:*:* 2.8.0 (including) 2.8.64 (excluding)
cpe:2.3:a:appleple:a-blog_cms:*:*:*:*:*:*:*:* 2.9.0 (including) 2.9.6 (excluding)
cpe:2.3:a:appleple:a-blog_cms:*:*:*:*:*:*:*:* 2.10.0 (including) 2.10.23 (excluding)