ZeroHour

Vulnerabilities

5 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-45990
A cross-site scripting (XSS) vulnerability in the component /signup_script.php of Ecommerce-Website v1.0 allows attackers to execute arbitrary web scripts or HT

A cross-site scripting (XSS) vulnerability in the component /signup_script.php of Ecommerce-Website v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the eMail parameter.

NVD description · AI analysis pending
6.1<1% PoC
  • ecommerce-website project ecommerce-website
CVE-2022-27357
+1 in the same advisory: …27346
Ecommerce-Website v1 was discovered to contain an arbitrary file upload vulnerability via /customer_register.php.

Ecommerce-Website v1 was discovered to contain an arbitrary file upload vulnerability via /customer_register.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.

NVD description · AI analysis pending
9.8
group max
4% PoC ×3
  • ecommerce-website project ecommerce-website
CVE-2022-27435
+1 in the same advisory: …27436
An unrestricted file upload at /public/admin/index.php?add_product of Ecommerce-Website v1.1.0 allows attackers to upload a webshell via the Product Image compo

An unrestricted file upload at /public/admin/index.php?add_product of Ecommerce-Website v1.1.0 allows attackers to upload a webshell via the Product Image component.

NVD description · AI analysis pending
8.8
group max
2% PoC ×3
  • ecommerce-website project ecommerce-website