ZeroHour

CVE-2018-9331

PoC
CVSS 3.1
7.5 high
EPSS
3%p84
Published
()
Modified
Description

An issue was discovered in zzcms 8.2. user/adv.php allows remote attackers to delete arbitrary files via directory traversal sequences in the oldimg parameter. This can be leveraged for database access by deleting install.lock.

Vendors
zzcms
Products
zzcms
Weakness
CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.