zzzcms kayıtları
zzzcms üreticisine ait 20 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 1 · %5
- Silahlaştırılmış
- 1 · %5
- Pre-auth RCE
- 9
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- 983 gün
Tekrar eden sınıflar
- CWE-434 Unrestricted Upload of File with Dangerous Type4
- CWE-94 Improper Control of Generation of Code ('Code Injection')3
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-352 Cross-Site Request Forgery (CSRF)2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
- CWE-80 Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
20 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
94Hemen | CVE-2019-9082Silahlaştırılmış | ThinkPHP before 3.2.4, as used in Open Source BMS v1.1.1 and other products, allows Remote Command Execution via public//?s=index/\think\appthinkphp · thinkphp · CWE-94 | Yüksek8,8 | KEV | %97,4 | 24 Şub 2019 |
56Planlayın | CVE-2022-23881Kavram kanıtı | ZZZCMS zzzphp v2.1.0 was discovered to contain a remote command execution (RCE) vulnerability via danger_key() at zzz_template.php.zzzcms · zzzphp | Kritik9,8 | — | %56,5 | 23 Mar 2022 |
41Planlayın | CVE-2019-10647Kavram kanıtı | ZZZCMS zzzphp v1.6.3 allows remote attackers to execute arbitrary PHP code via a .php URL in the plugins/ueditor/php/controller.php?action=czzzcms · zzzphp · CWE-434 | Kritik9,8 | — | %6,6 | 30 Mar 2019 |
40Planlayın | CVE-2021-32605İstismar yok | zzzcms zzzphp before 2.0.4 allows remote attackers to execute arbitrary OS commands by placing them in the keys parameter of a ?location=seazzzcms · zzzphp · CWE-78 | Kritik9,8 | — | %3,8 | 11 May 2021 |
40Planlayın | CVE-2019-17408İstismar yok | parserIfLabel in inc/zzz_template.php in ZZZCMS zzzphp 1.7.3 allows remote attackers to execute arbitrary code because the danger_key functizzzcms · zzzphp · CWE-94 | Kritik9,8 | — | %3,7 | 14 Eki 2019 |
40Planlayın | CVE-2020-18717İstismar yok | SQL Injection in ZZZCMS zzzphp 1.7.1 allows remote attackers to execute arbitrary code due to a lack of parameter filtering in inc/zzz_templzzzcms · zzzphp · CWE-89 | Kritik9,8 | — | %3,6 | 5 Şub 2021 |
40Planlayın | CVE-2019-16722İstismar yok | ZZZCMS zzzphp v1.7.2 has an insufficient protection mechanism against PHP Code Execution, because passthru bypasses an str_ireplace operatiozzzcms · zzzphp | Kritik9,8 | — | %3,1 | 23 Eyl 2019 |
40Planlayın | CVE-2020-20298İstismar yok | Eval injection vulnerability in the parserCommom method in the ParserTemplate class in zzz_template.php in zzzphp 1.7.2 allows remote attackzzzcms · zzzphp · CWE-94 | Kritik9,8 | — | %2,7 | 18 Ara 2020 |
40Planlayın | CVE-2020-24877İstismar yok | A SQL injection vulnerability in zzzphp v1.8.0 through /form/index.php?module=getjson may lead to a possible access restriction bypass.zzzcms · zzzphp · CWE-89 | Kritik9,8 | — | %2,1 | 15 Mar 2021 |
39İzleyin | CVE-2023-45554İstismar yok | File Upload vulnerability in zzzCMS v.2.1.9 allows a remote attacker to execute arbitrary code via modification of the imageext parameter frzzzcms · zzzcms · CWE-434 | Kritik9,8 | — | %1,5 | 25 Eki 2023 |
37İzleyin | CVE-2019-9041Kavram kanıtı | An issue was discovered in ZZZCMS zzzphp V1.6.1.zzzcms · zzzphp · CWE-917 | Yüksek7,2 | — | %31,4 | 23 Şub 2019 |
35İzleyin | CVE-2019-9182İstismar yok | There is a CSRF in ZZZCMS zzzphp V1.6.1 via a /admin015/save.php?act=editfile request.zzzcms · zzzphp · CWE-352 | Yüksek8,8 | — | %0,8 | 26 Şub 2019 |
35İzleyin | CVE-2023-5263İstismar yok | ZZZCMS Database Backup File save.php restore permissionzzzcms · zzzcms · CWE-275 | Yüksek8,8 | — | %0,6 | 29 Eyl 2023 |
35İzleyin | CVE-2020-19682İstismar yok | A Cross Site Request Forgery (CSRF) vulnerability exits in ZZZCMS V1.7.1 via the save_user funciton in save.php.zzzcms · zzzcms · CWE-352 | Yüksek8,8 | — | %0,5 | 9 Ara 2021 |
31İzleyin | CVE-2023-45555İstismar yok | File Upload vulnerability in zzzCMS v.2.1.9 allows a remote attacker to execute arbitrary code via a crafted file to the down_url function izzzcms · zzzcms · CWE-434 | Yüksek7,8 | — | %0,9 | 25 Eki 2023 |
30İzleyin | CVE-2019-16720İstismar yok | ZZZCMS zzzphp v1.7.2 does not properly restrict file upload in plugins/ueditor/php/controller.php?upfolder=news&action=catchimage, as demonszzzcms · zzzphp · CWE-434 | Yüksek7,5 | — | %1,4 | 23 Eyl 2019 |
30İzleyin | CVE-2018-20127İstismar yok | An issue was discovered in zzzphp cms 1.5.8.zzzcms · zzzphp · CWE-20 | Yüksek7,5 | — | %1,4 | 13 Ara 2018 |
24İzleyin | CVE-2023-45909İstismar yok | zzzcms v2.2.0 was discovered to contain an open redirect vulnerability.zzzcms · zzzphp · CWE-601 | Orta6,1 | — | %0,3 | 18 Eki 2023 |
21İzleyin | CVE-2020-19683İstismar yok | A Cross Site Scripting (XSS) exists in ZZZCMS V1.7.1 via an editfile action in save.php.zzzcms · zzzcms · CWE-79 | Orta5,4 | — | %0,6 | 9 Ara 2021 |
21İzleyin | CVE-2023-5582İstismar yok | ZZZCMS Personal Profile Page cross site scriptingzzzcms · zzzcms · CWE-80 | Orta5,4 | — | %0,5 | 14 Eki 2023 |
- CVE-2019-908294Hemen
ThinkPHP before 3.2.4, as used in Open Source BMS v1.1.1 and other products, allows Remote Command Execution via public//?s=index/\think\app
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %97thinkphp · thinkphp24 Şub 2019
- CVE-2022-2388156Planlayın
ZZZCMS zzzphp v2.1.0 was discovered to contain a remote command execution (RCE) vulnerability via danger_key() at zzz_template.php.
KritikCVSS 9,8Kavram kanıtıEPSS %57zzzcms · zzzphp23 Mar 2022
- CVE-2019-1064741Planlayın
ZZZCMS zzzphp v1.6.3 allows remote attackers to execute arbitrary PHP code via a .php URL in the plugins/ueditor/php/controller.php?action=c
KritikCVSS 9,8Kavram kanıtıEPSS %7zzzcms · zzzphp30 Mar 2019
- CVE-2021-3260540Planlayın
zzzcms zzzphp before 2.0.4 allows remote attackers to execute arbitrary OS commands by placing them in the keys parameter of a ?location=sea
KritikCVSS 9,8İstismar yokEPSS %4zzzcms · zzzphp11 May 2021
- CVE-2019-1740840Planlayın
parserIfLabel in inc/zzz_template.php in ZZZCMS zzzphp 1.7.3 allows remote attackers to execute arbitrary code because the danger_key functi
KritikCVSS 9,8İstismar yokEPSS %4zzzcms · zzzphp14 Eki 2019
- CVE-2020-1871740Planlayın
SQL Injection in ZZZCMS zzzphp 1.7.1 allows remote attackers to execute arbitrary code due to a lack of parameter filtering in inc/zzz_templ
KritikCVSS 9,8İstismar yokEPSS %4zzzcms · zzzphp5 Şub 2021
- CVE-2019-1672240Planlayın
ZZZCMS zzzphp v1.7.2 has an insufficient protection mechanism against PHP Code Execution, because passthru bypasses an str_ireplace operatio
KritikCVSS 9,8İstismar yokEPSS %3zzzcms · zzzphp23 Eyl 2019
- CVE-2020-2029840Planlayın
Eval injection vulnerability in the parserCommom method in the ParserTemplate class in zzz_template.php in zzzphp 1.7.2 allows remote attack
KritikCVSS 9,8İstismar yokEPSS %3zzzcms · zzzphp18 Ara 2020
- CVE-2020-2487740Planlayın
A SQL injection vulnerability in zzzphp v1.8.0 through /form/index.php?module=getjson may lead to a possible access restriction bypass.
KritikCVSS 9,8İstismar yokEPSS %2zzzcms · zzzphp15 Mar 2021
- CVE-2023-4555439İzleyin
File Upload vulnerability in zzzCMS v.2.1.9 allows a remote attacker to execute arbitrary code via modification of the imageext parameter fr
KritikCVSS 9,8İstismar yokEPSS %2zzzcms · zzzcms25 Eki 2023
- CVE-2019-904137İzleyin
An issue was discovered in ZZZCMS zzzphp V1.6.1.
YüksekCVSS 7,2Kavram kanıtıEPSS %31zzzcms · zzzphp23 Şub 2019
- CVE-2019-918235İzleyin
There is a CSRF in ZZZCMS zzzphp V1.6.1 via a /admin015/save.php?act=editfile request.
YüksekCVSS 8,8İstismar yokEPSS %1zzzcms · zzzphp26 Şub 2019
- CVE-2023-526335İzleyin
ZZZCMS Database Backup File save.php restore permission
YüksekCVSS 8,8İstismar yokEPSS %1zzzcms · zzzcms29 Eyl 2023
- CVE-2020-1968235İzleyin
A Cross Site Request Forgery (CSRF) vulnerability exits in ZZZCMS V1.7.1 via the save_user funciton in save.php.
YüksekCVSS 8,8İstismar yokEPSS %1zzzcms · zzzcms9 Ara 2021
- CVE-2023-4555531İzleyin
File Upload vulnerability in zzzCMS v.2.1.9 allows a remote attacker to execute arbitrary code via a crafted file to the down_url function i
YüksekCVSS 7,8İstismar yokEPSS %1zzzcms · zzzcms25 Eki 2023
- CVE-2019-1672030İzleyin
ZZZCMS zzzphp v1.7.2 does not properly restrict file upload in plugins/ueditor/php/controller.php?upfolder=news&action=catchimage, as demons
YüksekCVSS 7,5İstismar yokEPSS %1zzzcms · zzzphp23 Eyl 2019
- CVE-2018-2012730İzleyin
An issue was discovered in zzzphp cms 1.5.8.
YüksekCVSS 7,5İstismar yokEPSS %1zzzcms · zzzphp13 Ara 2018
- CVE-2023-4590924İzleyin
zzzcms v2.2.0 was discovered to contain an open redirect vulnerability.
OrtaCVSS 6,1İstismar yokEPSS %0zzzcms · zzzphp18 Eki 2023
- CVE-2020-1968321İzleyin
A Cross Site Scripting (XSS) exists in ZZZCMS V1.7.1 via an editfile action in save.php.
OrtaCVSS 5,4İstismar yokEPSS %1zzzcms · zzzcms9 Ara 2021
- CVE-2023-558221İzleyin
ZZZCMS Personal Profile Page cross site scripting
OrtaCVSS 5,4İstismar yokEPSS %1zzzcms · zzzcms14 Eki 2023