Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
zzcms vulnerabilities and exploits
(subscribe to this query)
6.8
CVSSv2
CVE-2018-14963
zzcms 8.3 has CSRF via the admin/adminadd.php?action=add URI.
Zzcms Zzcms 8.3.
7.5
CVSSv2
CVE-2018-13116
/user/del.php in zzcms 8.3 allows SQL injection via the tablename parameter after leveraging use of the zzcms_ask table.
Zzcms Zzcms 8.3.
6.4
CVSSv2
CVE-2018-13056
An issue exists on zzcms 8.3. There is a vulnerability at /user/del.php that can delete any file by placing its relative path into the zzcms_main table and then making an img add request. This can be leveraged for database access by deleting install.lock.
Zzcms Zzcms 8.3
6.4
CVSSv2
CVE-2018-9331
An issue exists in zzcms 8.2. user/adv.php allows remote malicious users to delete arbitrary files via directory traversal sequences in the oldimg parameter. This can be leveraged for database access by deleting install.lock.
Zzcms Zzcms 8.2
5
CVSSv2
CVE-2018-9309
An issue exists in zzcms 8.2. It allows SQL injection via the id parameter in a dl/dl_sendsms.php request.
Zzcms Zzcms 8.2
6.4
CVSSv2
CVE-2018-8969
An issue exists in zzcms 8.2. user/licence_save.php allows remote malicious users to delete arbitrary files via directory traversal sequences in the oldimg parameter in an action=modify request. This can be leveraged for database access by deleting install.lock.
Zzcms Zzcms 8.2
6.4
CVSSv2
CVE-2018-8965
An issue exists in zzcms 8.2. user/ppsave.php allows remote malicious users to delete arbitrary files via directory traversal sequences in the oldimg parameter in an action=modify request. This can be leveraged for database access by deleting install.lock.
Zzcms Zzcms 8.2
5
CVSSv2
CVE-2018-8966
An issue exists in zzcms 8.2. It allows PHP code injection via the siteurl parameter to install/index.php, as demonstrated by injecting a phpinfo() call into /inc/config.php.
Zzcms Zzcms 8.2
7.5
CVSSv2
CVE-2018-8967
An issue exists in zzcms 8.2. It allows SQL injection via the id parameter in an adv2.php?action=modify request.
Zzcms Zzcms 8.2
6.4
CVSSv2
CVE-2018-8968
An issue exists in zzcms 8.2. user/manage.php allows remote malicious users to delete arbitrary files via directory traversal sequences in the oldimg or oldflv parameter in an action=modify request. This can be leveraged for database access by deleting install.lock.
Zzcms Zzcms 8.2
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-29895
blind SQL injection
CVE-2024-5064
CVE-2023-52677
CVE-2023-52682
CVE-2024-30051
CVE-2024-35849
remote attackers
remote
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
3
4
5
6
7
8
9
NEXT »