CVE-2019-17408: Code Injection
Published Oct 14, 2019
·Updated
parserIfLabel in inc/zzztemplate.php in ZZZCMS zzzphp 1.7.3 allows remote attackers to execute arbitrary code because the dangerkey function can be bypassed via manipulations such as strtr.
Affected Software
1 affected component
ZZZCMS zzzphp=1.7.3
Event History
Oct 14, 2019
CVE Published
via MITRE·11:43 AM
Data Sourced
via MITRE·11:43 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2019-17408.
2
What is the severity of CVE-2019-17408?
CVE-2019-17408 has a severity rating of 9.8 (critical).
3
What software versions are affected by CVE-2019-17408?
ZZZCMS zzzphp version 1.7.3 is affected by CVE-2019-17408.
4
How can remote attackers exploit CVE-2019-17408?
Remote attackers can exploit CVE-2019-17408 by manipulating the danger_key function in inc/zzz_template.php to execute arbitrary code.
5
Is there a fix available for CVE-2019-17408?
Currently, there is no known fix available for CVE-2019-17408. It is recommended to update to a newer version of ZZZCMS zzzphp if one becomes available.