CVE-2016-9835
9.8
CRITICAL · CVSS 3.0 · EPSS 3.9% (pctl 90)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
Directory traversal vulnerability in file "jcss.php" in Zikula 1.3.x before 1.3.11 and 1.4.x before 1.4.4 on Windows allows a remote attacker to launch a PHP object injection by uploading a serialized file.
Scoring
| CVSS | 9.8 (CRITICAL, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 3.92% — more likely to be exploited than 90% of all CVEs |
| Weakness | CWE-77 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2016-12-05 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| zikula | zikula application framework |
References
- http://www.securityfocus.com/bid/95005
- https://github.com/zikula/core/blob/1.3/CHANGELOG-1.3.md
- https://github.com/zikula/core/blob/1.4/CHANGELOG-1.4.md
- https://github.com/zikula/core/issues/3237
- http://www.securityfocus.com/bid/95005
- https://github.com/zikula/core/blob/1.3/CHANGELOG-1.3.md
- https://github.com/zikula/core/blob/1.4/CHANGELOG-1.4.md
- https://github.com/zikula/core/issues/3237
→ the Explorer · watch your stack · NVD