cve/2018/CVE-2018-9331.md
2024-06-09 00:33:16 +00:00

764 B

CVE-2018-9331

Description

An issue was discovered in zzcms 8.2. user/adv.php allows remote attackers to delete arbitrary files via directory traversal sequences in the oldimg parameter. This can be leveraged for database access by deleting install.lock.

POC

Reference

Github

No PoCs found on GitHub currently.