VYPR

Zzcms

by Zzcms

Source repositories

CVEs (119)

  • CVE-2018-8965HigMar 24, 2018
    risk 0.49cvss 7.5epss 0.03

    An issue was discovered in zzcms 8.2. user/ppsave.php allows remote attackers to delete arbitrary files via directory traversal sequences in the oldimg parameter in an action=modify request. This can be leveraged for database access by deleting install.lock.

  • CVE-2025-0565HigJan 19, 2025
    risk 0.48cvss 7.3epss 0.01

    A vulnerability was found in ZZCMS 2023. It has been rated as critical. Affected by this issue is some unknown functionality of the file /index.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to…

  • CVE-2024-7927HigAug 19, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability classified as critical was found in ZZCMS 2023. Affected by this vulnerability is an unknown functionality of the file /admin/class.php?dowhat=modifyclass. The manipulation of the argument skin[] leads to path traversal. The attack can be launched remotely. The…

  • CVE-2024-7926HigAug 19, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability classified as critical has been found in ZZCMS 2023. Affected is an unknown function of the file /admin/about_edit.php?action=modify. The manipulation of the argument skin leads to path traversal. It is possible to launch the attack remotely. The exploit has been…

  • CVE-2022-40447HigSep 22, 2022
    risk 0.47cvss 7.2epss 0.01

    ZZCMS 2022 was discovered to contain a SQL injection vulnerability via the keyword parameter at /admin/baojia_list.php.

  • CVE-2022-40446HigSep 22, 2022
    risk 0.47cvss 7.2epss 0.01

    ZZCMS 2022 was discovered to contain a SQL injection vulnerability via the component /admin/sendmailto.php?tomail=&groupid=.

  • CVE-2019-12359HigJun 17, 2022
    risk 0.47cvss 7.2epss 0.01

    An issue was discovered in zzcms 2019. There is a SQL injection Vulnerability in /admin/ztliuyan_sendmail.php (when the attacker has admin authority) via the id parameter.

  • CVE-2019-12357HigJun 17, 2022
    risk 0.47cvss 7.2epss 0.01

    An issue was discovered in zzcms 2019. There is a SQL injection Vulnerability in /admin/deluser.php (when the attacker has admin authority) via the id parameter.

  • CVE-2019-12354HigJun 17, 2022
    risk 0.47cvss 7.2epss 0.01

    An issue was discovered in zzcms 2019. There is a SQL injection Vulnerability in /admin/showbad.php (when the attacker has admin authority) via the id parameter.

  • CVE-2019-12353HigJun 17, 2022
    risk 0.47cvss 7.2epss 0.01

    An issue was discovered in zzcms 2019. There is a SQL injection Vulnerability in /admin/dl_sendmail.php (when the attacker has admin authority) via the id parameter.

  • CVE-2021-46436HigApr 8, 2022
    risk 0.47cvss 7.2epss 0.01

    An issue was discovered in ZZCMS 2021. There is a SQL injection vulnerability in ad_manage.php.

  • CVE-2021-40280HigDec 9, 2021
    risk 0.47cvss 7.2epss 0.01

    An SQL Injection vulnerablitly exits in zzcms 8.2, 8.3, 2020, and 2021 via the id parameter in admin/dl_sendmail.php.

  • CVE-2021-40279HigDec 9, 2021
    risk 0.47cvss 7.2epss 0.01

    An SQL Injection vulnerability exists in zzcms 8.2, 8.3, 2020, and 2021 via the id parameter in admin/bad.php.

  • CVE-2020-19822HigAug 26, 2021
    risk 0.47cvss 7.2epss 0.03

    A remote code execution (RCE) vulnerability in template_user.php of ZZCMS version 2018 allows attackers to execute arbitrary PHP code via the "ml" and "title" parameters.

  • CVE-2018-17416HigMar 7, 2019
    risk 0.47cvss 7.2epss 0.01

    A SQL injection vulnerability exists in zzcms v8.3 via the /admin/adclass.php bigclassid parameter.

  • CVE-2018-18790HigOct 29, 2018
    risk 0.47cvss 7.2epss 0.01

    An issue was discovered in zzcms 8.3. SQL Injection exists in admin/special_add.php via a zxbigclassid cookie. (This needs an admin user login.)

  • CVE-2018-18788HigOct 29, 2018
    risk 0.47cvss 7.2epss 0.01

    An issue was discovered in zzcms 8.3. SQL Injection exists in admin/classmanage.php via the tablename parameter. (This needs an admin user login.)

  • CVE-2018-18784HigOct 29, 2018
    risk 0.47cvss 7.2epss 0.01

    An issue was discovered in zzcms 8.3. SQL Injection exists in admin/tagmanage.php via the tabletag parameter. (This needs an admin user login.)

  • CVE-2018-17798MedSep 30, 2018
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in zzcms 8.3. user/ztconfig.php allows remote attackers to delete arbitrary files via an absolute pathname in the oldimg parameter in an action=modify request. This can be leveraged for database access by deleting install.lock.

  • CVE-2018-17797MedSep 30, 2018
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in zzcms 8.3. user/zssave.php allows remote attackers to delete arbitrary files via directory traversal sequences in the oldimg parameter in an action=modify request. This can be leveraged for database access by deleting install.lock.

Page 4 of 6