ZeroHour

Vulnerabilities

18 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-44838
Automotive Shop Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /services/view_service.php.

Automotive Shop Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /services/view_service.php.

NVD description · AI analysis pending
7.2<1% PoC
  • automotive shop management system project automotive shop management system
CVE-2022-44858
+2 in the same advisory: …44859 …44860
Automotive Shop Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /asms/products/view_product.php.

Automotive Shop Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /asms/products/view_product.php.

NVD description · AI analysis pending
7.2<1% PoC
  • automotive shop management system project automotive shop management system
CVE-2022-44280
Automotive Shop Management System v1.0 is vulnerable to Delete any file via /asms/classes/Master.php?f=delete_img.

Automotive Shop Management System v1.0 is vulnerable to Delete any file via /asms/classes/Master.php?f=delete_img.

NVD description · AI analysis pending
6.5<1% PoC
  • automotive shop management system project automotive shop management system
CVE-2022-44378
Automotive Shop Management System v1.0 is vulnerable to SQL via /asms/classes/Master.php?f=delete_mechanic.

Automotive Shop Management System v1.0 is vulnerable to SQL via /asms/classes/Master.php?f=delete_mechanic.

NVD description · AI analysis pending
7.2<1% PoC
  • automotive shop management system project automotive shop management system
CVE-2022-44403
+1 in the same advisory: …44402
Automotive Shop Management System v1.0 is vulnerable to SQL Injection via /asms/admin/?page=user/manage_user&id=.

Automotive Shop Management System v1.0 is vulnerable to SQL Injection via /asms/admin/?page=user/manage_user&id=.

NVD description · AI analysis pending
7.2<1% PoC
  • automotive shop management system project automotive shop management system
CVE-2022-30493
+2 in the same advisory: …30495 …30494
In oretnom23 Automotive Shop Management System v1.0, the product id parameter suffers from a blind SQL Injection Vulnerability allowing remote attackers to dump

In oretnom23 Automotive Shop Management System v1.0, the product id parameter suffers from a blind SQL Injection Vulnerability allowing remote attackers to dump all database credential and gain admin access(privilege escalation).

NVD description · AI analysis pending
9.8
group max
2% PoC
  • automotive shop management system project automotive shop management system
CVE-2022-30463
+1 in the same advisory: …30458
Automotive Shop Management System v1.0 is vulnerable to SQL Injection via /asms/classes/Master.php?f=delete_product.

Automotive Shop Management System v1.0 is vulnerable to SQL Injection via /asms/classes/Master.php?f=delete_product.

NVD description · AI analysis pending
8.8
group max
<1% PoC
  • automotive shop management system project automotive shop management system