A Cross Site Scripting (XSS) exists in ZZZCMS V1.7.1 via an editfile action in save.php.
A Cross Site Request Forgery (CSRF) vulnerability exits in ZZZCMS V1.7.1 via the saveuser funciton in save.php.
SQL Injection in ZZZCMS zzzphp 1.7.1 allows remote attackers to execute arbitrary code due to a lack of parameter filtering in inc/zzztemplate.php.