Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2019-9041 PoC — ZZZCMS zzzphp 代码注入漏洞

Source
Associated Vulnerability
Title:ZZZCMS zzzphp 代码注入漏洞 (CVE-2019-9041)
Description:ZZZCMS zzzphp是一套内容管理系统(CMS)。 ZZZCMS zzzphp V1.6.1版本中存在安全漏洞,该漏洞源于搜索页面对搜索模版的解析过滤不严严格。攻击者可利用该漏洞执行PHP代码。
Description
ZZZCMS zzzphp V1.6.1 is vulnerable to remote code execution via the inc/zzz_template.php file because the parserIfLabel() function's filtering is not strict, resulting in PHP code execution as demonstrated by the if:assert substring.
File Snapshot

id: CVE-2019-9041 info: name: ZZZCMS 1.6.1 - Remote Code Execution author: pikpikcu severity: ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.