CVE-2018-6029

Source
https://cve.org/CVERecord?id=CVE-2018-6029
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-6029.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2018-6029
Published
2018-01-23T06:29:00.400Z
Modified
2026-07-08T16:41:17.183125Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
[none]
Details

The copy function in application/admin/controller/Article.php in NoneCms 1.3.0 allows remote attackers to access the content of internal and external network resources via Server Side Request Forgery (SSRF), because URL validation only considers whether the URL contains the "csdn" substring.

References

Affected packages

Git / github.com/nangge/nonecms

Affected ranges

Type
GIT
Repo
https://github.com/nangge/nonecms
Events
Database specific
{
    "cpe": "cpe:2.3:a:5none:nonecms:1.3.0:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "1.3.0"
        },
        {
            "last_affected": "1.3.0"
        }
    ],
    "source": "CPE_STRING"
}

Affected versions

1.*
1.3.0
v1.*
v1.3.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-6029.json"