ZeroHour

Vulnerabilities

5 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-36306
A Cross Site Scripting (XSS) vulnerability in Adiscon Aiscon LogAnalyzer through 4.1.13 allows a remote attacker to execute arbitrary code via the asktheoracle.

A Cross Site Scripting (XSS) vulnerability in Adiscon Aiscon LogAnalyzer through 4.1.13 allows a remote attacker to execute arbitrary code via the asktheoracle.php, details.php, index.php, search.php, export.php, reports.php, and statistics.php components.

NVD description · AI analysis pending
6.15% PoC
  • adiscon loganalyzer
CVE-2023-34600
Adiscon LogAnalyzer v4.1.13 and before is vulnerable to SQL Injection.

Adiscon LogAnalyzer v4.1.13 and before is vulnerable to SQL Injection.

NVD description · AI analysis pending
9.824% PoC
  • adiscon loganalyzer
CVE-2022-36664
Password Manager for IIS 2.0 has a cross-site scripting (XSS) vulnerability via the /isapi/PasswordManager.dll ResultURL parameter.

Password Manager for IIS 2.0 has a cross-site scripting (XSS) vulnerability via the /isapi/PasswordManager.dll ResultURL parameter.

NVD description · AI analysis pending
6.14% PoC
  • adiscon password manager for iis
CVE-2021-31738
Adiscon LogAnalyzer 4.1.10 and 4.1.11 allow login.php XSS.

Adiscon LogAnalyzer 4.1.10 and 4.1.11 allow login.php XSS.

NVD description · AI analysis pending
6.1<1% PoC
  • adiscon loganalyzer
CVE-2018-19877
login.php in Adiscon LogAnalyzer before 4.1.7 has XSS via the Login Button Referer field.

login.php in Adiscon LogAnalyzer before 4.1.7 has XSS via the Login Button Referer field.

NVD description · AI analysis pending
6.119% PoC
  • adiscon loganalyzer