VendorsZZZCMSzzzphp1.7.2
Vulnerabilities

ZZZCMS zzzphp 1.7.2

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2019-16722
ZZZCMS zzzphp v1.7.2 has an insufficient protection mechanism against PHP Code Execution, because passthru bypasses an str_ireplace operation.
Published 2019-09-23 · Modified
9.8EPSS 0.031
CVE-2020-20298
Eval injection vulnerability in the parserCommom method in the ParserTemplate class in zzz_template.php in zzzphp 1.7.2 allows remote attackers to execute arbitrary commands.
Published 2020-12-18 · Modified
9.8EPSS 0.027
CVE-2019-16720
ZZZCMS zzzphp v1.7.2 does not properly restrict file upload in plugins/ueditor/php/controller.php?upfolder=news&action=catchimage, as demonstrated by uploading a .htaccess or .php5 file.
Published 2019-09-23 · Modified
7.5EPSS 0.014