Vulnerability Description
zzcms version 8.3 and earlier contains a SQL Injection vulnerability in zt/top.php line 5 that can result in could be attacked by sql injection in zzcms in nginx. This attack appear to be exploitable via running zzcms in nginx.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Zzcms | Zzcms | <= 8.3 |
Related Weaknesses (CWE)
References
- https://gist.github.com/Lz1y/3388fa886a3e10edd2a7e93d3c3e5b6cExploitThird Party Advisory
- https://gist.github.com/Lz1y/3388fa886a3e10edd2a7e93d3c3e5b6cExploitThird Party Advisory
FAQ
What is CVE-2018-1000653?
CVE-2018-1000653 is a vulnerability with a CVSS score of 9.8 (CRITICAL). zzcms version 8.3 and earlier contains a SQL Injection vulnerability in zt/top.php line 5 that can result in could be attacked by sql injection in zzcms in nginx. This attack appear to be exploitable ...
How severe is CVE-2018-1000653?
CVE-2018-1000653 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2018-1000653?
Check the references section above for vendor advisories and patch information. Affected products include: Zzcms Zzcms.