Vulnerabilities (CVE)

Filtered by vendor Nibbleblog Subscribe
Filtered by product Nibbleblog
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-23356 1 Nibbleblog 1 Nibbleblog 2021-07-21 5.0 MEDIUM 7.5 HIGH
dmin/kernel/api/login.class.phpin in nibbleblog v3.7.1c allows type juggling for login bypass because == is used instead of === for password hashes, which mishandles hashes that begin with 0e followed by exclusively numerical characters.
CVE-2018-16604 1 Nibbleblog 1 Nibbleblog 2018-11-14 6.5 MEDIUM 7.2 HIGH
An issue was discovered in Nibbleblog v4.0.5. With an admin's username and password, an attacker can execute arbitrary PHP code by changing the username because the username is surrounded by double quotes (e.g., "${phpinfo()}").