First published: Mon Oct 14 2019(Updated: )
parserIfLabel in inc/zzz_template.php in ZZZCMS zzzphp 1.7.3 allows remote attackers to execute arbitrary code because the danger_key function can be bypassed via manipulations such as strtr.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ZZZCMS zzzphp | =1.7.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2019-17408.
CVE-2019-17408 has a severity rating of 9.8 (critical).
ZZZCMS zzzphp version 1.7.3 is affected by CVE-2019-17408.
Remote attackers can exploit CVE-2019-17408 by manipulating the danger_key function in inc/zzz_template.php to execute arbitrary code.
Currently, there is no known fix available for CVE-2019-17408. It is recommended to update to a newer version of ZZZCMS zzzphp if one becomes available.