CVE-2021-32605

Severity CVSS v4.0:
Pending analysis
Type:
CWE-78 OS Command Injections
Publication date:
11/05/2021
Last modified:
19/05/2021

Description

zzzcms zzzphp before 2.0.4 allows remote attackers to execute arbitrary OS commands by placing them in the keys parameter of a ?location=search URI, as demonstrated by an OS command within an "if" "end if" block.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:zzzcms:zzzphp:*:*:*:*:*:*:*:* 2.0.4 (excluding)