Vulnerability index

Browse CVEs

101 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.4 CVE-2018-14962 zzcms 8.3 has stored XSS related to the content variable in user/manage.php and zt/show.php. Zzcms No fix yet Fix from $1,6002018-08-06 CRITICAL 9.8 CVE-2018-13116 /user/del.php in zzcms 8.3 allows SQL injection via the tablename parameter after leveraging use of the zzcms_ask table. Zzcms No fix yet Fix from $2,3002018-07-03 HIGH 7.5 CVE-2018-13056 An issue was discovered on zzcms 8.3. There is a vulnerability at /user/del.php that can delete any file by placing its relative path into the zzcms_… Zzcms No fix yet Fix from $1,9502018-07-02 HIGH 7.5 CVE-2018-9331 An issue was discovered in zzcms 8.2. user/adv.php allows remote attackers to delete arbitrary files via directory traversal sequences in the oldimg … Zzcms No fix yet Fix from $1,9502018-04-07 CRITICAL 9.8 CVE-2018-9309 An issue was discovered in zzcms 8.2. It allows SQL injection via the id parameter in a dl/dl_sendsms.php request. Zzcms No fix yet Fix from $2,3002018-04-05 CRITICAL 9.8 CVE-2018-8967 An issue was discovered in zzcms 8.2. It allows SQL injection via the id parameter in an adv2.php?action=modify request. Zzcms No fix yet Fix from $2,3002018-03-24 HIGH 7.5 CVE-2018-8965 An issue was discovered in zzcms 8.2. user/ppsave.php allows remote attackers to delete arbitrary files via directory traversal sequences in the oldi… Zzcms No fix yet Fix from $1,9502018-03-24 HIGH 7.5 CVE-2018-8966 An issue was discovered in zzcms 8.2. It allows PHP code injection via the siteurl parameter to install/index.php, as demonstrated by injecting a php… Zzcms No fix yet Fix from $1,9502018-03-24 HIGH 7.5 CVE-2018-8968 An issue was discovered in zzcms 8.2. user/manage.php allows remote attackers to delete arbitrary files via directory traversal sequences in the oldi… Zzcms No fix yet Fix from $1,9502018-03-24 HIGH 7.5 CVE-2018-8969 An issue was discovered in zzcms 8.2. user/licence_save.php allows remote attackers to delete arbitrary files via directory traversal sequences in th… Zzcms No fix yet Fix from $1,9502018-03-24 MEDIUM 5.3 CVE-2018-7434 zzcms 8.2 allows remote attackers to discover the full path via a direct request to 3/qq_connect2.0/API/class/ErrorCase.class.php or 3/ucenter_api/co… Zzcms No fix yet Fix from $1,6002018-02-24