Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
7.5
CVSSv2
CVE-2015-7346
Published: 07/06/2017 Updated: 12/06/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P
Subscribe to Zcms Project
Vulnerability Summary
SQL injection vulnerability in ZCMS 1.1.
Vulnerable Product
Search on Vulmon
Subscribe to Product
zcms project zcms 1.1
Exploits
Exploit DB: ZCMS 1.1 - Multiple Vulnerabilities
# Exploit Title: SQL Injection & Persistent XSS # Google Dork: intitle: SQL Injection & Persistent XSS # Date: 2015-06-12 # Exploit Author: John Page ( hyp3rlinx ) # Website: hyp3rlinxaltervistaorg # Vendor Homepage: zencherrycom # Software Link: sourceforgenet/projects/zencherrycms # Version: 11 # Tested on: windows 7 on Apache Tomc ...
References
CWE-89
https://www.exploit-db.com/exploits/37272/
http://packetstormsecurity.com/files/132286/ZCMS-1.1-Cross-Site-Scripting-SQL-Injection.html
http://hyp3rlinx.altervista.org/advisories/AS-ZCMS0612.txt
https://nvd.nist.gov
https://www.exploit-db.com/exploits/37272/
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2022-38028
CVE-2024-32406
CVE-2024-25624
IMAP
CVE-2024-2310
CVE-2024-0874
CVE-2024-20359
XXE
remote code execution
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started