CVE-2021-32605: OS Command Injection
Published May 11, 2021
·Updated
zzzcms zzzphp before 2.0.4 allows remote attackers to execute arbitrary OS commands by placing them in the keys parameter of a ?location=search URI, as demonstrated by an OS command within an "if" "end if" block.
Affected Software
1 affected component
ZZZCMS zzzphp<2.0.4
Event History
May 11, 2021
CVE Published
via MITRE·10:25 PM
Data Sourced
via MITRE·10:25 PM
Description
Frequently Asked Questions
1
What is CVE-2021-32605?
CVE-2021-32605 is a vulnerability in zzzcms zzzphp before version 2.0.4 that allows remote attackers to execute arbitrary OS commands.
2
How can remote attackers exploit CVE-2021-32605?
Remote attackers can exploit CVE-2021-32605 by placing arbitrary OS commands in the keys parameter of a ?location=search URI.
3
What is the severity of CVE-2021-32605?
CVE-2021-32605 has a severity rating of 9.8 (Critical).
4
What software version is affected by CVE-2021-32605?
CVE-2021-32605 affects zzzphp version up to exclusive 2.0.4.
5
How can I fix CVE-2021-32605?
To fix CVE-2021-32605, upgrade to zzzphp version 2.0.4 or later.