First published: Tue May 11 2021(Updated: )
zzzcms zzzphp before 2.0.4 allows remote attackers to execute arbitrary OS commands by placing them in the keys parameter of a ?location=search URI, as demonstrated by an OS command within an "if" "end if" block.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ZZZCMS zzzphp | <2.0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-32605 is a vulnerability in zzzcms zzzphp before version 2.0.4 that allows remote attackers to execute arbitrary OS commands.
Remote attackers can exploit CVE-2021-32605 by placing arbitrary OS commands in the keys parameter of a ?location=search URI.
CVE-2021-32605 has a severity rating of 9.8 (Critical).
CVE-2021-32605 affects zzzphp version up to exclusive 2.0.4.
To fix CVE-2021-32605, upgrade to zzzphp version 2.0.4 or later.