Pineapple Pavilion ZBLOGCN .COM

Official Z-Blog Blog

Notes on repairing Blind-XXE arbitrary file reading vulnerability and file inclusion vulnerability

 Jiupin Sesame official white bread sky Hail.the. Judge.1994.BluRay. X264.2Audio. AAC.720p. SDHF-NORMTEAM.mkv_20150309_152909.312.jpg

Recently, we received two security reports from Uyun.com, pointing out that Z-BlogPHP has major security vulnerabilities. After the confirmation of the development team, it is confirmed that the vulnerability does exist, and the repair patch has been released to the update server, please update as soon as possible!!

Repair method:

  • Enter the Z-BlogPHP background application center, enter the [System Update and Verification] item, click [Verify the current version of the system core file], and update the relevant files.

  • Delete the zb_install directory.

If users of version 1.4 cannot update and verify online, please download the latest installation package on the official website and upload it with FTP once.


We are very sorry that our negligence has caused a security threat to your website. In the future, we will pay more attention to the security requirements in PHP development.

Thank you very much, Black Cloud White Hat phith0n  And 'Rain We also welcome other white hats to help us check our security.

Powered By Z-BlogPHP 1.7.3

ZBLOGCN. COM All rights reserved E ICP B No. 19031813 - 6 Shoot the clouds again Provide CDN and cloud storage services

It is strictly prohibited to use Z-BLOG to engage in any illegal activities, and illegal websites are prohibited to use Z-BLOG and related procedures| Illegal and Bad Information Reporting Center