CVE-2018-14961
- EPSS 0.26%
- Published 06.08.2018 15:29:00
- Last modified 21.11.2024 03:50:11
dl/dl_sendmail.php in zzcms 8.3 has SQL Injection via the sql parameter.
CVE-2018-14962
- EPSS 0.21%
- Published 06.08.2018 15:29:00
- Last modified 21.11.2024 03:50:11
zzcms 8.3 has stored XSS related to the content variable in user/manage.php and zt/show.php.
CVE-2018-14963
- EPSS 0.14%
- Published 06.08.2018 15:29:00
- Last modified 21.11.2024 03:50:11
zzcms 8.3 has CSRF via the admin/adminadd.php?action=add URI.
CVE-2018-13116
- EPSS 0.26%
- Published 03.07.2018 19:29:01
- Last modified 21.11.2024 03:46:28
/user/del.php in zzcms 8.3 allows SQL injection via the tablename parameter after leveraging use of the zzcms_ask table.
CVE-2018-13056
- EPSS 0.24%
- Published 02.07.2018 15:29:00
- Last modified 21.11.2024 03:46:19
An issue was discovered on zzcms 8.3. There is a vulnerability at /user/del.php that can delete any file by placing its relative path into the zzcms_main table and then making an img add request. This can be leveraged for database access by deleting ...
CVE-2018-9331
- EPSS 0.75%
- Published 07.04.2018 02:29:00
- Last modified 21.11.2024 04:15:20
An issue was discovered in zzcms 8.2. user/adv.php allows remote attackers to delete arbitrary files via directory traversal sequences in the oldimg parameter. This can be leveraged for database access by deleting install.lock.
CVE-2018-9309
- EPSS 0.55%
- Published 05.04.2018 01:29:07
- Last modified 21.11.2024 04:15:18
An issue was discovered in zzcms 8.2. It allows SQL injection via the id parameter in a dl/dl_sendsms.php request.
CVE-2018-8965
- EPSS 0.81%
- Published 24.03.2018 18:29:00
- Last modified 21.11.2024 04:14:41
An issue was discovered in zzcms 8.2. user/ppsave.php allows remote attackers to delete arbitrary files via directory traversal sequences in the oldimg parameter in an action=modify request. This can be leveraged for database access by deleting insta...
CVE-2018-8966
- EPSS 0.6%
- Published 24.03.2018 18:29:00
- Last modified 21.11.2024 04:14:42
An issue was discovered in zzcms 8.2. It allows PHP code injection via the siteurl parameter to install/index.php, as demonstrated by injecting a phpinfo() call into /inc/config.php.
CVE-2018-8967
- EPSS 0.48%
- Published 24.03.2018 18:29:00
- Last modified 21.11.2024 04:14:42
An issue was discovered in zzcms 8.2. It allows SQL injection via the id parameter in an adv2.php?action=modify request.