CVE-2020-18717: SQL Injection
SQL Injection in ZZZCMS zzzphp 1.7.1 allows remote attackers to execute arbitrary code due to a lack of parameter filtering in inc/zzztemplate.php.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-18717?
CVE-2020-18717 is a SQL Injection vulnerability in ZZZCMS zzzphp 1.7.1 that allows remote attackers to execute arbitrary code.
How severe is CVE-2020-18717?
CVE-2020-18717 has a severity rating of 9.8 (Critical).
How does CVE-2020-18717 work?
CVE-2020-18717 is caused by a lack of parameter filtering in the 'inc/zzz_template.php' file, which allows remote attackers to exploit a SQL Injection vulnerability and execute arbitrary code.
Is there a fix for CVE-2020-18717?
Yes, to fix CVE-2020-18717, update ZZZCMS zzzphp to a version that includes a fix for the SQL Injection vulnerability.
Where can I find more information about CVE-2020-18717?
More information about CVE-2020-18717 can be found at the following link: [https://www.seebug.org/vuldb/ssvid-98031](https://www.seebug.org/vuldb/ssvid-98031)