A sensitive information disclosure vulnerability exists in ZZCMS v.2023 and before within the eginfo.php file located at /3/E_bak5.1/upload/. When accessed with the query parameter phome=ShowPHPInfo, the application executes the phpinfo() function, which exposes detailed information about the PHP environment, including server configuration, loaded modules, and environment variables.
Metrics
Affected Vendors & Products
References
History
Wed, 04 Sep 2024 19:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-200 | |
CPEs | cpe:2.3:a:zzcms:zzcms:2023:*:*:*:*:*:*:* | |
Metrics |
cvssV3_1
|
ssvc
|
Wed, 04 Sep 2024 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Zzcms
Zzcms zzcms |
|
Weaknesses | CWE-79 | |
CPEs | cpe:2.3:a:zzcms:zzcms:*:*:*:*:*:*:*:* | |
Vendors & Products |
Zzcms
Zzcms zzcms |
|
Metrics |
cvssV3_1
|
Wed, 04 Sep 2024 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A sensitive information disclosure vulnerability exists in ZZCMS v.2023 and before within the eginfo.php file located at /3/E_bak5.1/upload/. When accessed with the query parameter phome=ShowPHPInfo, the application executes the phpinfo() function, which exposes detailed information about the PHP environment, including server configuration, loaded modules, and environment variables. | |
References |
|
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2024-09-04T00:00:00
Updated: 2024-09-04T18:20:44.775Z
Reserved: 2024-08-21T00:00:00
Link: CVE-2024-44820
Vulnrichment
Updated: 2024-09-04T18:20:32.653Z
NVD
Status : Modified
Published: 2024-09-04T15:15:13.997
Modified: 2024-09-04T19:35:13.010
Link: CVE-2024-44820
Redhat
No data.