Show filters
27 Total Results
Displaying 11-20 of 27
Sort by:
Attacker Value
Unknown

CVE-2018-18788

Disclosure Date: October 29, 2018 (last updated November 27, 2024)
An issue was discovered in zzcms 8.3. SQL Injection exists in admin/classmanage.php via the tablename parameter. (This needs an admin user login.)
0
Attacker Value
Unknown

CVE-2018-18784

Disclosure Date: October 29, 2018 (last updated November 27, 2024)
An issue was discovered in zzcms 8.3. SQL Injection exists in admin/tagmanage.php via the tabletag parameter. (This needs an admin user login.)
0
Attacker Value
Unknown

CVE-2018-18790

Disclosure Date: October 29, 2018 (last updated November 27, 2024)
An issue was discovered in zzcms 8.3. SQL Injection exists in admin/special_add.php via a zxbigclassid cookie. (This needs an admin user login.)
0
Attacker Value
Unknown

CVE-2018-18786

Disclosure Date: October 29, 2018 (last updated November 27, 2024)
An issue was discovered in zzcms 8.3. SQL Injection exists in ajax/zs.php via a pxzs cookie.
0
Attacker Value
Unknown

CVE-2018-18787

Disclosure Date: October 29, 2018 (last updated November 27, 2024)
An issue was discovered in zzcms 8.3. SQL Injection exists in zs/zs.php via a pxzs cookie.
0
Attacker Value
Unknown

CVE-2018-18785

Disclosure Date: October 29, 2018 (last updated November 27, 2024)
An issue was discovered in zzcms 8.3. SQL Injection exists in zs/subzs.php with a zzcmscpid cookie to zs/search.php.
0
Attacker Value
Unknown

CVE-2018-18789

Disclosure Date: October 29, 2018 (last updated November 27, 2024)
An issue was discovered in zzcms 8.3. SQL Injection exists in zt/top.php via a Host HTTP header to zt/news.php.
0
Attacker Value
Unknown

CVE-2018-18792

Disclosure Date: October 29, 2018 (last updated November 27, 2024)
An issue was discovered in zzcms 8.3. SQL Injection exists in zs/zs_list.php via a pxzs cookie.
0
Attacker Value
Unknown

CVE-2018-17797

Disclosure Date: September 30, 2018 (last updated November 27, 2024)
An issue was discovered in zzcms 8.3. user/zssave.php allows remote attackers to delete arbitrary files via directory traversal sequences in the oldimg parameter in an action=modify request. This can be leveraged for database access by deleting install.lock.
0
Attacker Value
Unknown

CVE-2018-17798

Disclosure Date: September 30, 2018 (last updated November 27, 2024)
An issue was discovered in zzcms 8.3. user/ztconfig.php allows remote attackers to delete arbitrary files via an absolute pathname in the oldimg parameter in an action=modify request. This can be leveraged for database access by deleting install.lock.
0