cumtxujiabin/CmsPoc

cumtxujiabin/CmsPoc

Releases0
Stars1

CVE History

CVEPublishedCVSS v3CVSS v2
6.5 MEDIUM

SeaCMS 6.61 allows remote attackers to execute arbitrary code because parseIf() in include/main.class.php does not block use of $GLOBALS.

6.4 MEDIUM

An issue was discovered in zzcms 8.3. It allows remote attackers to delete arbitrary files via directory traversal sequences in the flv parameter. This can be leveraged for database access by deleting install.lock.