Show filters
22 Total Results
Displaying 21-22 of 22
Sort by:
Attacker Value
Unknown
CVE-2020-20285
Disclosure Date: December 18, 2020 (last updated February 22, 2025)
There is a XSS in the user login page in zzcms 2019. Users can inject js code by the referer header via user/login.php
0
Attacker Value
Unknown
CVE-2019-9078
Disclosure Date: February 24, 2019 (last updated November 27, 2024)
zzcms 2019 has XSS via an arbitrary user/ask.php?do=modify parameter because inc/stopsqlin.php does not block a mixed-case string such as sCrIpT.
0