CVE-2018-8966

An issue was discovered in zzcms 8.2. It allows PHP code injection via the siteurl parameter to install/index.php, as demonstrated by injecting a phpinfo() call into /inc/config.php.
Configurations

Configuration 1

cpe:2.3:a:zzcms:zzcms:8.2:*:*:*:*:*:*:*

Information

Published : 2018-03-24 06:29

Updated : 2022-11-01 07:12


NVD link : CVE-2018-8966

Mitre link : CVE-2018-8966

Products Affected
No products.
CWE