Z-BlogPHP 1.6.0 Valyria is affected by incorrect access control. PHP loose comparison and a magic hash can be used to bypass authentication. zbuser/plugin/passwordvisit/include.php:passwordvisitinput_password() uses loose comparison to authenticate, which can be bypassed via magic hash values.
{
"extracted_events": [
{
"introduced": "1.6.0"
},
{
"last_affected": "1.6.0"
}
],
"source": [
"CPE_STRING",
"REFERENCES"
],
"cpe": "cpe:2.3:a:zblogcn:z-blogphp:1.6.0:*:*:*:*:*:*:*"
}