First published: Mon Aug 20 2018(Updated: )
zzcms version 8.3 and earlier contains a SQL Injection vulnerability in zt/top.php line 5 that can result in could be attacked by sql injection in zzcms in nginx. This attack appear to be exploitable via running zzcms in nginx.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ZZCMS | <=8.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-1000653 is categorized as a high severity SQL Injection vulnerability.
To fix CVE-2018-1000653, upgrade to a version of zzcms later than 8.3 that addresses this vulnerability.
Exploiting CVE-2018-1000653 can allow attackers to execute arbitrary SQL queries on the database.
Yes, CVE-2018-1000653 appears to be particularly exploitable when zzcms is running in an nginx web server environment.
Users and organizations running zzcms version 8.3 or earlier are affected by CVE-2018-1000653.