CVE-2022-40443
- EPSS 11.23%
- Veröffentlicht 22.09.2022 14:15:09
- Zuletzt bearbeitet 27.05.2025 17:15:23
An absolute path traversal vulnerability in ZZCMS 2022 allows attackers to obtain sensitive information via a crafted GET request sent to /one/siteinfo.php.
CVE-2022-40444
- EPSS 0.25%
- Veröffentlicht 22.09.2022 14:15:09
- Zuletzt bearbeitet 27.05.2025 17:15:23
ZZCMS 2022 was discovered to contain a full path disclosure vulnerability via the page /admin/index.PHP? _server.
CVE-2022-40446
- EPSS 0.24%
- Veröffentlicht 22.09.2022 14:15:09
- Zuletzt bearbeitet 27.05.2025 16:15:27
ZZCMS 2022 was discovered to contain a SQL injection vulnerability via the component /admin/sendmailto.php?tomail=&groupid=.
CVE-2022-40447
- EPSS 0.26%
- Veröffentlicht 22.09.2022 14:15:09
- Zuletzt bearbeitet 27.05.2025 16:15:27
ZZCMS 2022 was discovered to contain a SQL injection vulnerability via the keyword parameter at /admin/baojia_list.php.
CVE-2019-12352
- EPSS 0.24%
- Veröffentlicht 17.06.2022 13:15:11
- Zuletzt bearbeitet 21.11.2024 04:22:38
An issue was discovered in zzcms 2019. There is a SQL injection Vulnerability in /dl/dl_sendmail.php (when the attacker has dls_print authority) via a dlid cookie.
CVE-2019-12353
- EPSS 0.26%
- Veröffentlicht 17.06.2022 13:15:11
- Zuletzt bearbeitet 21.11.2024 04:22:39
An issue was discovered in zzcms 2019. There is a SQL injection Vulnerability in /admin/dl_sendmail.php (when the attacker has admin authority) via the id parameter.
CVE-2019-12354
- EPSS 0.26%
- Veröffentlicht 17.06.2022 13:15:11
- Zuletzt bearbeitet 21.11.2024 04:22:39
An issue was discovered in zzcms 2019. There is a SQL injection Vulnerability in /admin/showbad.php (when the attacker has admin authority) via the id parameter.
CVE-2019-12355
- EPSS 0.24%
- Veröffentlicht 17.06.2022 13:15:11
- Zuletzt bearbeitet 21.11.2024 04:22:39
An issue was discovered in zzcms 2019. There is a SQL injection Vulnerability in /user/dls_print.php (when the attacker has dls_print authority) via the id parameter.
CVE-2019-12356
- EPSS 0.28%
- Veröffentlicht 17.06.2022 13:15:11
- Zuletzt bearbeitet 21.11.2024 04:22:39
An issue was discovered in zzcms 2019. There is a SQL injection Vulnerability in /user/dls_download.php (when the attacker has dls_download authority) via the id parameter.
CVE-2019-12357
- EPSS 0.26%
- Veröffentlicht 17.06.2022 13:15:11
- Zuletzt bearbeitet 21.11.2024 04:22:39
An issue was discovered in zzcms 2019. There is a SQL injection Vulnerability in /admin/deluser.php (when the attacker has admin authority) via the id parameter.