Vulnerabilities
Vulnerable Software
Zzzcms:  >> Zzzphp  >> 1.7.2  Security Vulnerabilities
zzzcms zzzphp before 2.0.4 allows remote attackers to execute arbitrary OS commands by placing them in the keys parameter of a ?location=search URI, as demonstrated by an OS command within an "if" "end if" block.
CVSS Score
9.8
EPSS Score
0.219
Published
2021-05-11
Eval injection vulnerability in the parserCommom method in the ParserTemplate class in zzz_template.php in zzzphp 1.7.2 allows remote attackers to execute arbitrary commands.
CVSS Score
9.8
EPSS Score
0.064
Published
2020-12-18
ZZZCMS zzzphp v1.7.2 does not properly restrict file upload in plugins/ueditor/php/controller.php?upfolder=news&action=catchimage, as demonstrated by uploading a .htaccess or .php5 file.
CVSS Score
7.5
EPSS Score
0.003
Published
2019-09-23
ZZZCMS zzzphp v1.7.2 has an insufficient protection mechanism against PHP Code Execution, because passthru bypasses an str_ireplace operation.
CVSS Score
9.8
EPSS Score
0.036
Published
2019-09-23


Contact Us

Shodan ® - All rights reserved