Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w2v7-6jjj-cwx5

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

zzzcms zzzphp before 2.0.4 allows remote attackers to execute arbitrary OS commands by placing them in the keys parameter of a ?location=search URI, as demonstrated by an OS command within an "if" "end if" block.

zzzcms zzzphp before 2.0.4 allows remote attackers to execute arbitrary OS commands by placing them in the keys parameter of a ?location=search URI, as demonstrated by an OS command within an "if" "end if" block.

EPSS

Процентиль: 96%
0.21913
Средний

Дефекты

CWE-78

Связанные уязвимости

CVSS3: 9.8
nvd
больше 4 лет назад

zzzcms zzzphp before 2.0.4 allows remote attackers to execute arbitrary OS commands by placing them in the keys parameter of a ?location=search URI, as demonstrated by an OS command within an "if" "end if" block.

EPSS

Процентиль: 96%
0.21913
Средний

Дефекты

CWE-78