/user/del.php in zzcms 8.3 allows SQL injection via the tablename parameter after leveraging use of the zzcms_ask table.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2018-07-03T19:00:00
Updated: 2024-08-05T08:52:50.455Z
Reserved: 2018-07-03T00:00:00
Link: CVE-2018-13116
Vulnrichment
No data.
NVD
Status : Modified
Published: 2018-07-03T19:29:01.747
Modified: 2024-11-21T03:46:28.307
Link: CVE-2018-13116
Redhat
No data.