An issue was discovered in ZZZCMS zzzphp V1.6.1. In the inc/zzz_template.php file, the parserIfLabel() function's filtering is not strict, resulting in PHP code execution, as demonstrated by the if:assert substring.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2019-02-23T18:00:00
Updated: 2024-08-04T21:38:45.585Z
Reserved: 2019-02-23T00:00:00
Link: CVE-2019-9041
Vulnrichment
No data.
NVD
Status : Analyzed
Published: 2019-02-23T18:29:00.300
Modified: 2021-07-21T11:39:23.747
Link: CVE-2019-9041
Redhat
No data.