ZeroHour

Vulnerabilities

4 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-6352
The default configuration of Aquaforest TIFF Server allows access to arbitrary file paths, subject to any restrictions imposed by Internet Information Services

The default configuration of Aquaforest TIFF Server allows access to arbitrary file paths, subject to any restrictions imposed by Internet Information Services (IIS) or Microsoft Windows. Depending on how a web application uses and configures TIFF Server, a remote attacker may be able to enumerate files or directories, traverse directories, bypass authentication, or access restricted files.

NVD description · AI analysis pending
5.31% PoC
  • aquaforest tiff server
CVE-2020-9325
+2 in the same advisory: …9324 …9323
Aquaforest TIFF Server 4.0 allows Unauthenticated Arbitrary File Download.

Aquaforest TIFF Server 4.0 allows Unauthenticated Arbitrary File Download.

NVD description · AI analysis pending
7.5
group max
2% PoC
  • aquaforest tiff server