Vulnerabilities > CVE-2019-9041 - Expression Language Injection vulnerability in Zzzcms Zzzphp 1.6.1

047910
CVSS 7.2 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
HIGH
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
zzzcms
CWE-917
exploit available

Summary

An issue was discovered in ZZZCMS zzzphp V1.6.1. In the inc/zzz_template.php file, the parserIfLabel() function's filtering is not strict, resulting in PHP code execution, as demonstrated by the if:assert substring.

Vulnerable Configurations

Part Description Count
Application
Zzzcms
1

Exploit-Db

fileexploits/php/webapps/46454.txt
idEDB-ID:46454
last seen2019-02-25
modified2019-02-25
platformphp
port
published2019-02-25
reporterExploit-DB
sourcehttps://www.exploit-db.com/download/46454
titlezzzphp CMS 1.6.1 - Remote Code Execution
typewebapps

Packetstorm