Vulnerability index

Browse CVEs

87 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2019-8411 admin/dl_data.php in zzcms 2018 (2018-10-19) allows remote attackers to delete arbitrary files via action=del&filename=../ directory traversal. Zzcms No fix yet Fix from $1,9502019-02-17 CRITICAL 9.8 CVE-2018-18786 An issue was discovered in zzcms 8.3. SQL Injection exists in ajax/zs.php via a pxzs cookie. Zzcms No fix yet Fix from $2,3002018-10-29 CRITICAL 9.8 CVE-2018-18787 An issue was discovered in zzcms 8.3. SQL Injection exists in zs/zs.php via a pxzs cookie. Zzcms No fix yet Fix from $2,3002018-10-29 CRITICAL 9.8 CVE-2018-18789 An issue was discovered in zzcms 8.3. SQL Injection exists in zt/top.php via a Host HTTP header to zt/news.php. Zzcms No fix yet Fix from $2,3002018-10-29 CRITICAL 9.8 CVE-2018-18791 An issue was discovered in zzcms 8.3. SQL Injection exists in zs/search.php via a pxzs cookie. Zzcms No fix yet Fix from $2,3002018-10-29 CRITICAL 9.8 CVE-2018-18792 An issue was discovered in zzcms 8.3. SQL Injection exists in zs/zs_list.php via a pxzs cookie. Zzcms No fix yet Fix from $2,3002018-10-29 HIGH 7.2 CVE-2018-18788 An issue was discovered in zzcms 8.3. SQL Injection exists in admin/classmanage.php via the tablename parameter. (This needs an admin user login.) Zzcms No fix yet Fix from $1,9502018-10-29 HIGH 7.2 CVE-2018-18790 An issue was discovered in zzcms 8.3. SQL Injection exists in admin/special_add.php via a zxbigclassid cookie. (This needs an admin user login.) Zzcms No fix yet Fix from $1,9502018-10-29 CRITICAL 9.8 CVE-2018-18785 An issue was discovered in zzcms 8.3. SQL Injection exists in zs/subzs.php with a zzcmscpid cookie to zs/search.php. Zzcms No fix yet Fix from $2,3002018-10-29 HIGH 7.2 CVE-2018-18784 An issue was discovered in zzcms 8.3. SQL Injection exists in admin/tagmanage.php via the tabletag parameter. (This needs an admin user login.) Zzcms No fix yet Fix from $1,9502018-10-29 MEDIUM 6.5 CVE-2018-17797 An issue was discovered in zzcms 8.3. user/zssave.php allows remote attackers to delete arbitrary files via directory traversal sequences in the oldi… Zzcms No fix yet Fix from $1,6002018-09-30 MEDIUM 6.5 CVE-2018-17798 An issue was discovered in zzcms 8.3. user/ztconfig.php allows remote attackers to delete arbitrary files via an absolute pathname in the oldimg para… Zzcms No fix yet Fix from $1,6002018-09-30 CRITICAL 9.8 CVE-2018-17136 zzcms 8.3 contains a SQL Injection vulnerability in /user/check.php via a Client-Ip HTTP header. Zzcms No fix yet Fix from $2,3002018-09-17 HIGH 7.5 CVE-2018-16344 An issue was discovered in zzcms 8.3. It allows remote attackers to delete arbitrary files via directory traversal sequences in the flv parameter. Th… Zzcms No fix yet Fix from $1,9502018-09-02 CRITICAL 9.8 CVE-2018-14961 dl/dl_sendmail.php in zzcms 8.3 has SQL Injection via the sql parameter. Zzcms No fix yet Fix from $2,3002018-08-06 HIGH 8.8 CVE-2018-14963 zzcms 8.3 has CSRF via the admin/adminadd.php?action=add URI. Zzcms No fix yet Fix from $1,9502018-08-06 MEDIUM 5.4 CVE-2018-14962 zzcms 8.3 has stored XSS related to the content variable in user/manage.php and zt/show.php. Zzcms No fix yet Fix from $1,6002018-08-06 CRITICAL 9.8 CVE-2018-13116 /user/del.php in zzcms 8.3 allows SQL injection via the tablename parameter after leveraging use of the zzcms_ask table. Zzcms No fix yet Fix from $2,3002018-07-03 HIGH 7.5 CVE-2018-13056 An issue was discovered on zzcms 8.3. There is a vulnerability at /user/del.php that can delete any file by placing its relative path into the zzcms_… Zzcms No fix yet Fix from $1,9502018-07-02 HIGH 7.5 CVE-2018-9331 An issue was discovered in zzcms 8.2. user/adv.php allows remote attackers to delete arbitrary files via directory traversal sequences in the oldimg … Zzcms No fix yet Fix from $1,9502018-04-07 CRITICAL 9.8 CVE-2018-9309 An issue was discovered in zzcms 8.2. It allows SQL injection via the id parameter in a dl/dl_sendsms.php request. Zzcms No fix yet Fix from $2,3002018-04-05 CRITICAL 9.8 CVE-2018-8967 An issue was discovered in zzcms 8.2. It allows SQL injection via the id parameter in an adv2.php?action=modify request. Zzcms No fix yet Fix from $2,3002018-03-24 HIGH 7.5 CVE-2018-8965 An issue was discovered in zzcms 8.2. user/ppsave.php allows remote attackers to delete arbitrary files via directory traversal sequences in the oldi… Zzcms No fix yet Fix from $1,9502018-03-24 HIGH 7.5 CVE-2018-8966 An issue was discovered in zzcms 8.2. It allows PHP code injection via the siteurl parameter to install/index.php, as demonstrated by injecting a php… Zzcms No fix yet Fix from $1,9502018-03-24 HIGH 7.5 CVE-2018-8968 An issue was discovered in zzcms 8.2. user/manage.php allows remote attackers to delete arbitrary files via directory traversal sequences in the oldi… Zzcms No fix yet Fix from $1,9502018-03-24 HIGH 7.5 CVE-2018-8969 An issue was discovered in zzcms 8.2. user/licence_save.php allows remote attackers to delete arbitrary files via directory traversal sequences in th… Zzcms No fix yet Fix from $1,9502018-03-24 MEDIUM 5.3 CVE-2018-7434 zzcms 8.2 allows remote attackers to discover the full path via a direct request to 3/qq_connect2.0/API/class/ErrorCase.class.php or 3/ucenter_api/co… Zzcms No fix yet Fix from $1,6002018-02-24