Security Advisory

CVE-2018-16344

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2018-09-02 18:00:00
Last updated 2024-08-05 10:24:31
Assigner mitre
State PUBLISHED

Description

An issue was discovered in zzcms 8.3. It allows remote attackers to delete arbitrary files via directory traversal sequences in the flv parameter. This can be leveraged for database access by deleting install.lock.