Vendor Zzzcms First view 2019-02-23
Product Zzzphp Last view 2019-02-26
Version 1.6.1 Type Application
CPE Product cpe:2.3:a:zzzcms:zzzphp

Activity : Overall

Related : CVE

  Date Alert Description
8.8 2019-02-26 CVE-2019-9182

There is a CSRF in ZZZCMS zzzphp V1.6.1 via a /admin015/save.php?act=editfile request. It allows PHP code injection by providing a filename in the file parameter, and providing file content in the filetext parameter.

7.2 2019-02-23 CVE-2019-9041

An issue was discovered in ZZZCMS zzzphp V1.6.1. In the inc/zzz_template.php file, the parserIfLabel() function's filtering is not strict, resulting in PHP code execution, as demonstrated by the if:assert substring.

CWE : Common Weakness Enumeration

33% (1) CWE-352 Cross-Site Request Forgery (CSRF)
33% (1) CWE-94 Failure to Control Generation of Code ('Code Injection')
33% (1) CWE-20 Improper Input Validation