ZeroHour

Vulnerabilities

8 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-0417
+1 in the same advisory: …0412
A vulnerability, which was classified as critical, was found in DeShang DSShop up to 2.1.5.

A vulnerability, which was classified as critical, was found in DeShang DSShop up to 2.1.5. This affects an unknown part of the file application/home/controller/MemberAuth.php. The manipulation of the argument member_info leads to path traversal: '../filedir'. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-250437 was assigned to this vulnerability.

NVD description · AI analysis pending
9.81% PoC
  • csdeshang dsshop
CVE-2024-0416
+2 in the same advisory: …0415 …0411
A vulnerability, which was classified as critical, has been found in DeShang DSMall up to 5.0.3.

A vulnerability, which was classified as critical, has been found in DeShang DSMall up to 5.0.3. Affected by this issue is some unknown functionality of the file application/home/controller/MemberAuth.php. The manipulation of the argument file_name leads to path traversal: '../filedir'. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-250436.

NVD description · AI analysis pending
9.8
group max
<1%
  • csdeshang dsmall
CVE-2024-0414
A vulnerability classified as problematic has been found in DeShang DSCMS up to 3.1.2/7.1.

A vulnerability classified as problematic has been found in DeShang DSCMS up to 3.1.2/7.1. Affected is an unknown function of the file public/install.php. The manipulation leads to improper access controls. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-250434 is the identifier assigned to this vulnerability.

NVD description · AI analysis pending
9.8<1%
  • csdeshang dscms
CVE-2024-0413
A vulnerability was found in DeShang DSKMS up to 3.1.2.

A vulnerability was found in DeShang DSKMS up to 3.1.2. It has been rated as problematic. This issue affects some unknown processing of the file public/install.php. The manipulation leads to improper access controls. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-250433 was assigned to this vulnerability.

NVD description · AI analysis pending
9.8<1%
  • csdeshang dskms
CVE-2024-0358
A vulnerability was found in DeShang DSO2O up to 4.1.0.

A vulnerability was found in DeShang DSO2O up to 4.1.0. It has been classified as critical. This affects an unknown part of the file /install/install.php. The manipulation leads to improper access controls. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-250125 was assigned to this vulnerability.

NVD description · AI analysis pending
7.5<1%
  • csdeshang dso2o