CVE-2021-40282
- EPSS 0.26%
- Published 09.12.2021 17:15:07
- Last modified 21.11.2024 06:23:49
An SQL Injection vulnerability exists in zzcms 8.2, 8.3, 2020, abd 2021 in dl/dl_download.php. when registering ordinary users.
CVE-2021-40279
- EPSS 0.27%
- Published 09.12.2021 16:15:08
- Last modified 21.11.2024 06:23:48
An SQL Injection vulnerability exists in zzcms 8.2, 8.3, 2020, and 2021 via the id parameter in admin/bad.php.
CVE-2021-40280
- EPSS 0.27%
- Published 09.12.2021 16:15:08
- Last modified 21.11.2024 06:23:48
An SQL Injection vulnerablitly exits in zzcms 8.2, 8.3, 2020, and 2021 via the id parameter in admin/dl_sendmail.php.
CVE-2020-19957
- EPSS 0.4%
- Published 14.10.2021 15:15:08
- Last modified 21.11.2024 05:09:30
A SQL injection vulnerability has been discovered in zz cms version 2019 which allows attackers to retrieve sensitive data via the id parameter on the /dl/dl_print.php page.
CVE-2020-19959
- EPSS 0.4%
- Published 14.10.2021 15:15:08
- Last modified 21.11.2024 05:09:30
A SQL injection vulnerability has been discovered in zz cms version 2019 which allows attackers to retrieve sensitive data via the dlid parameter in the /dl/dl_sendmail.php page cookie.
CVE-2020-19960
- EPSS 0.4%
- Published 14.10.2021 15:15:08
- Last modified 21.11.2024 05:09:31
A SQL injection vulnerability has been discovered in zz cms version 2019 which allows attackers to retrieve sensitive data via the dlid parameter in the /dl/dl_sendsms.php page cookie.
CVE-2020-19961
- EPSS 0.79%
- Published 14.10.2021 15:15:08
- Last modified 21.11.2024 05:09:31
A SQL injection vulnerability has been discovered in zz cms version 2019 which allows attackers to retrieve sensitive data via the component subzs.php.
CVE-2020-19822
- EPSS 3.4%
- Published 26.08.2021 03:15:08
- Last modified 21.11.2024 05:09:24
A remote code execution (RCE) vulnerability in template_user.php of ZZCMS version 2018 allows attackers to execute arbitrary PHP code via the "ml" and "title" parameters.
CVE-2020-35973
- EPSS 0.21%
- Published 03.06.2021 21:15:07
- Last modified 21.11.2024 05:28:37
An issue was discovered in zzcms2020. There is a XSS vulnerability that can insert and execute JS code arbitrarily via /user/manage.php.
CVE-2019-12348
- EPSS 0.4%
- Published 24.05.2021 16:15:07
- Last modified 21.11.2024 04:22:38
An issue was discovered in zzcms 2019. SQL Injection exists in user/ztconfig.php via the daohang or img POST parameter.