ZeroHour

CVE-2018-1000653

PoC
CVSS 3.0
9.8 critical
EPSS
1%p66
Published
()
Modified
Description

zzcms version 8.3 and earlier contains a SQL Injection vulnerability in zt/top.php line 5 that can result in could be attacked by sql injection in zzcms in nginx. This attack appear to be exploitable via running zzcms in nginx.

Vendors
zzcms
Products
zzcms
Weakness
CWE-89
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.