Zzcms
by Zzcms
Source repositories
CVEs (119)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-17412 | Cri | 0.64 | 9.8 | 0.02 | Mar 7, 2019 | zzcms v8.3 contains a SQL Injection vulnerability in /user/logincheck.php via an X-Forwarded-For HTTP header. | ||
| CVE-2018-18792 | Cri | 0.64 | 9.8 | 0.01 | Oct 29, 2018 | An issue was discovered in zzcms 8.3. SQL Injection exists in zs/zs_list.php via a pxzs cookie. | ||
| CVE-2018-18791 | Cri | 0.64 | 9.8 | 0.02 | Oct 29, 2018 | An issue was discovered in zzcms 8.3. SQL Injection exists in zs/search.php via a pxzs cookie. | ||
| CVE-2018-18789 | Cri | 0.64 | 9.8 | 0.01 | Oct 29, 2018 | An issue was discovered in zzcms 8.3. SQL Injection exists in zt/top.php via a Host HTTP header to zt/news.php. | ||
| CVE-2018-18787 | Cri | 0.64 | 9.8 | 0.01 | Oct 29, 2018 | An issue was discovered in zzcms 8.3. SQL Injection exists in zs/zs.php via a pxzs cookie. | ||
| CVE-2018-18786 | Cri | 0.64 | 9.8 | 0.01 | Oct 29, 2018 | An issue was discovered in zzcms 8.3. SQL Injection exists in ajax/zs.php via a pxzs cookie. | ||
| CVE-2018-18785 | Cri | 0.64 | 9.8 | 0.01 | Oct 29, 2018 | An issue was discovered in zzcms 8.3. SQL Injection exists in zs/subzs.php with a zzcmscpid cookie to zs/search.php. | ||
| CVE-2018-17136 | Cri | 0.64 | 9.8 | 0.01 | Sep 17, 2018 | zzcms 8.3 contains a SQL Injection vulnerability in /user/check.php via a Client-Ip HTTP header. | ||
| CVE-2018-1000653 | Cri | 0.64 | 9.8 | 0.01 | Aug 20, 2018 | zzcms version 8.3 and earlier contains a SQL Injection vulnerability in zt/top.php line 5 that can result in could be attacked by sql injection in zzcms in nginx. This attack appear to be exploitable via running zzcms in nginx. | ||
| CVE-2018-14961 | Cri | 0.64 | 9.8 | 0.02 | Aug 6, 2018 | dl/dl_sendmail.php in zzcms 8.3 has SQL Injection via the sql parameter. | ||
| CVE-2018-13116 | Cri | 0.64 | 9.8 | 0.01 | Jul 3, 2018 | /user/del.php in zzcms 8.3 allows SQL injection via the tablename parameter after leveraging use of the zzcms_ask table. | ||
| CVE-2018-9309 | Cri | 0.64 | 9.8 | 0.02 | Apr 5, 2018 | An issue was discovered in zzcms 8.2. It allows SQL injection via the id parameter in a dl/dl_sendsms.php request. | ||
| CVE-2018-8967 | Cri | 0.64 | 9.8 | 0.02 | Mar 24, 2018 | An issue was discovered in zzcms 8.2. It allows SQL injection via the id parameter in an adv2.php?action=modify request. | ||
| CVE-2024-44817 | Hig | 0.57 | 8.8 | 0.01 | Sep 4, 2024 | SQL Injection vulnerability in ZZCMS v.2023 and before allows a remote attacker to obtain sensitive information via the id parameter in the adv2.php component. | ||
| CVE-2023-36162 | Hig | 0.57 | 8.8 | 0.01 | Jul 3, 2023 | Cross Site Request Forgery vulnerability in ZZCMS v.2023 and earlier allows a remote attacker to gain privileges via the add function in adminlist.php. | ||
| CVE-2019-12358 | Hig | 0.57 | 8.8 | 0.01 | Jun 17, 2022 | An issue was discovered in zzcms 2019. There is a SQL injection Vulnerability in /dl/dl_sendsms.php (when the attacker has dls_print authority) via a dlid cookie. | ||
| CVE-2019-12356 | Hig | 0.57 | 8.8 | 0.01 | Jun 17, 2022 | An issue was discovered in zzcms 2019. There is a SQL injection Vulnerability in /user/dls_download.php (when the attacker has dls_download authority) via the id parameter. | ||
| CVE-2019-12355 | Hig | 0.57 | 8.8 | 0.01 | Jun 17, 2022 | An issue was discovered in zzcms 2019. There is a SQL injection Vulnerability in /user/dls_print.php (when the attacker has dls_print authority) via the id parameter. | ||
| CVE-2019-12352 | Hig | 0.57 | 8.8 | 0.01 | Jun 17, 2022 | An issue was discovered in zzcms 2019. There is a SQL injection Vulnerability in /dl/dl_sendmail.php (when the attacker has dls_print authority) via a dlid cookie. | ||
| CVE-2020-19682 | Hig | 0.57 | 8.8 | 0.01 | Dec 9, 2021 | A Cross Site Request Forgery (CSRF) vulnerability exits in ZZZCMS V1.7.1 via the save_user funciton in save.php. |
- risk 0.64cvss 9.8epss 0.02
zzcms v8.3 contains a SQL Injection vulnerability in /user/logincheck.php via an X-Forwarded-For HTTP header.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in zzcms 8.3. SQL Injection exists in zs/zs_list.php via a pxzs cookie.
- risk 0.64cvss 9.8epss 0.02
An issue was discovered in zzcms 8.3. SQL Injection exists in zs/search.php via a pxzs cookie.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in zzcms 8.3. SQL Injection exists in zt/top.php via a Host HTTP header to zt/news.php.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in zzcms 8.3. SQL Injection exists in zs/zs.php via a pxzs cookie.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in zzcms 8.3. SQL Injection exists in ajax/zs.php via a pxzs cookie.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in zzcms 8.3. SQL Injection exists in zs/subzs.php with a zzcmscpid cookie to zs/search.php.
- risk 0.64cvss 9.8epss 0.01
zzcms 8.3 contains a SQL Injection vulnerability in /user/check.php via a Client-Ip HTTP header.
- risk 0.64cvss 9.8epss 0.01
zzcms version 8.3 and earlier contains a SQL Injection vulnerability in zt/top.php line 5 that can result in could be attacked by sql injection in zzcms in nginx. This attack appear to be exploitable via running zzcms in nginx.
- risk 0.64cvss 9.8epss 0.02
dl/dl_sendmail.php in zzcms 8.3 has SQL Injection via the sql parameter.
- risk 0.64cvss 9.8epss 0.01
/user/del.php in zzcms 8.3 allows SQL injection via the tablename parameter after leveraging use of the zzcms_ask table.
- risk 0.64cvss 9.8epss 0.02
An issue was discovered in zzcms 8.2. It allows SQL injection via the id parameter in a dl/dl_sendsms.php request.
- risk 0.64cvss 9.8epss 0.02
An issue was discovered in zzcms 8.2. It allows SQL injection via the id parameter in an adv2.php?action=modify request.
- risk 0.57cvss 8.8epss 0.01
SQL Injection vulnerability in ZZCMS v.2023 and before allows a remote attacker to obtain sensitive information via the id parameter in the adv2.php component.
- risk 0.57cvss 8.8epss 0.01
Cross Site Request Forgery vulnerability in ZZCMS v.2023 and earlier allows a remote attacker to gain privileges via the add function in adminlist.php.
- risk 0.57cvss 8.8epss 0.01
An issue was discovered in zzcms 2019. There is a SQL injection Vulnerability in /dl/dl_sendsms.php (when the attacker has dls_print authority) via a dlid cookie.
- risk 0.57cvss 8.8epss 0.01
An issue was discovered in zzcms 2019. There is a SQL injection Vulnerability in /user/dls_download.php (when the attacker has dls_download authority) via the id parameter.
- risk 0.57cvss 8.8epss 0.01
An issue was discovered in zzcms 2019. There is a SQL injection Vulnerability in /user/dls_print.php (when the attacker has dls_print authority) via the id parameter.
- risk 0.57cvss 8.8epss 0.01
An issue was discovered in zzcms 2019. There is a SQL injection Vulnerability in /dl/dl_sendmail.php (when the attacker has dls_print authority) via a dlid cookie.
- risk 0.57cvss 8.8epss 0.01
A Cross Site Request Forgery (CSRF) vulnerability exits in ZZZCMS V1.7.1 via the save_user funciton in save.php.
Page 2 of 6