Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
zzcms zzcms vulnerabilities and exploits
(subscribe to this query)
9.8
CVSSv3
CVE-2021-43703
An Incorrect Access Control vulnerability exists in zzcms less than or equal to 2019 via admin.php. After disabling JavaScript, you can directly access the administrator console.
Zzcms Zzcms
9.8
CVSSv3
CVE-2018-17136
zzcms 8.3 contains a SQL Injection vulnerability in /user/check.php via a Client-Ip HTTP header.
Zzcms Zzcms 8.3
5.3
CVSSv3
CVE-2021-45286
Directory Traversal vulnerability exists in ZZCMS 2021 via the skin parameter in 1) index.php, 2) bottom.php, and 3) top_index.php.
Zzcms Zzcms 2021
7.5
CVSSv3
CVE-2021-45347
An Incorrect Access Control vulnerability exists in zzcms 8.2, which lets a malicious user bypass authentication by changing the user name in the cookie to use any password.
Zzcms Zzcms 8.2
5.3
CVSSv3
CVE-2022-40443
An absolute path traversal vulnerability in ZZCMS 2022 allows malicious users to obtain sensitive information via a crafted GET request sent to /one/siteinfo.php.
Zzcms Zzcms 2022
5.3
CVSSv3
CVE-2022-40444
ZZCMS 2022 exists to contain a full path disclosure vulnerability via the page /admin/index.PHP? _server.
Zzcms Zzcms 2022
7.2
CVSSv3
CVE-2022-40446
ZZCMS 2022 exists to contain a SQL injection vulnerability via the component /admin/sendmailto.php?tomail=&groupid=.
Zzcms Zzcms 2022
7.2
CVSSv3
CVE-2022-40447
ZZCMS 2022 exists to contain a SQL injection vulnerability via the keyword parameter at /admin/baojia_list.php.
Zzcms Zzcms 2022
5.3
CVSSv3
CVE-2018-7434
zzcms 8.2 allows remote malicious users to discover the full path via a direct request to 3/qq_connect2.0/API/class/ErrorCase.class.php or 3/ucenter_api/code/friend.php.
Zzcms Zzcms 8.2
7.2
CVSSv3
CVE-2018-18788
An issue exists in zzcms 8.3. SQL Injection exists in admin/classmanage.php via the tablename parameter. (This needs an admin user login.)
Zzcms Zzcms 8.3
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-23692
malicious code
XML injection
CVE-2024-28020
CVE-2024-35252
CVE-2024-5833
CVE-2024-30066
injection
CVE-2024-23282
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
NEXT »