SQL Injection in ZZZCMS zzzphp 1.7.1 allows remote attackers to execute arbitrary code due to a lack of parameter filtering in inc/zzztemplate.php.
A Cross Site Request Forgery (CSRF) vulnerability exits in ZZZCMS V1.7.1 via the saveuser funciton in save.php.
A Cross Site Scripting (XSS) exists in ZZZCMS V1.7.1 via an editfile action in save.php.