RSS   Vulnerabilities for 'Zzcms'   RSS

2018-04-06
 
CVE-2018-9331

CWE-22
 

 
An issue was discovered in zzcms 8.2. user/adv.php allows remote attackers to delete arbitrary files via directory traversal sequences in the oldimg parameter. This can be leveraged for database access by deleting install.lock.

 
2018-04-04
 
CVE-2018-9309

CWE-89
 

 
An issue was discovered in zzcms 8.2. It allows SQL injection via the id parameter in a dl/dl_sendsms.php request.

 
2018-03-24
 
CVE-2018-8969

CWE-22
 

 
An issue was discovered in zzcms 8.2. user/licence_save.php allows remote attackers to delete arbitrary files via directory traversal sequences in the oldimg parameter in an action=modify request. This can be leveraged for database access by deleting install.lock.

 
 
CVE-2018-8968

CWE-22
 

 
An issue was discovered in zzcms 8.2. user/manage.php allows remote attackers to delete arbitrary files via directory traversal sequences in the oldimg or oldflv parameter in an action=modify request. This can be leveraged for database access by deleting install.lock.

 
 
CVE-2018-8967

CWE-89
 

 
An issue was discovered in zzcms 8.2. It allows SQL injection via the id parameter in an adv2.php?action=modify request.

 
 
CVE-2018-8966

CWE-94
 

 
An issue was discovered in zzcms 8.2. It allows PHP code injection via the siteurl parameter to install/index.php, as demonstrated by injecting a phpinfo() call into /inc/config.php.

 
 
CVE-2018-8965

CWE-22
 

 
An issue was discovered in zzcms 8.2. user/ppsave.php allows remote attackers to delete arbitrary files via directory traversal sequences in the oldimg parameter in an action=modify request. This can be leveraged for database access by deleting install.lock.

 
2018-02-23
 
CVE-2018-7434

CWE-22
 

 
zzcms 8.2 allows remote attackers to discover the full path via a direct request to 3/qq_connect2.0/API/class/ErrorCase.class.php or 3/ucenter_api/code/friend.php.

 


Copyright 2018, cxsecurity.com

 

Back to Top