References https://nvd.nist.gov/vuln/detail/CVE-2022-23881 https://cvefeed.io/vuln/detail/CVE-2022-23881 https://access.redhat.com/security/cve/cve-2022-23881 https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2022/CVE-2022-23881.yaml https://avd.aliyun.com/detail?id=AVD-2022-23881 https://jvndb.jvn.jp/ja/contents/2022/JVNDB-2022-007203.html https://github.com/metaStor/Vuls/blob/main/zzzcms/zzzphp%20V2.1.0%20RCE/zzzphp%20V2.1.0%20RCE.md https://s4e.io/tools/zzzcms-zzzphp-2-1-0-remote-code-execution-cve-2022-23881
Related VulnerabilitiesPoCCVE-2019-11043: PHP-FPM Path Info Buffer Underflow - Remote Code ExecutionPoCCVE-2026-48611: phpBB < 3.3.17 - Authentication BypassPoCCVE-2026-46364: phpMyFAQ <= 4.1.1 - SQL InjectionPoCCVE-2026-6433: FlipperCode Custom CSS, JS & PHP <= 2.0.7 - Remote Code ExecutionphpVMS /importer 未授权访问漏洞(CVE-2026-42569)PoCphpjabbers-event-booking-xss: PHPJabbers Event Booking Calendar - Reflected XSSphpMyFAQ /api/captcha SQL 注入漏洞PoCCVE-2026-42569: phpVMS < 7.0.6 - Legacy Importer Authorization BypassphpVMS存在权限绕过漏洞(CVE-2026-42569)PoCCVE-2020-26935: phpMyAdmin < 5.0.3 - SQL InjectionPoCphp-prober-exposure: PHP Prober - ExposurePoCcakephp-debugkit-exposure: CakePHP - Debug Kit Toolbar ExposurePoCCVE-2025-69200: phpMyFAQ - Configuration Backup Disclosure