ZeroHour

Vulnerabilities

6 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-30890
Cross Site Scripting vulnerability in ED01-CMS v.1.0 allows an attacker to obtain sensitive information via the categories.php component.

Cross Site Scripting vulnerability in ED01-CMS v.1.0 allows an attacker to obtain sensitive information via the categories.php component.

NVD description · AI analysis pending
4.7<1% PoC
  • ed01-cms project ed01-cms
CVE-2022-28524
+1 in the same advisory: …28525
ED01-CMS v20180505 was discovered to contain a SQL injection vulnerability via the component post.php.

ED01-CMS v20180505 was discovered to contain a SQL injection vulnerability via the component post.php.

NVD description · AI analysis pending
9.8
group max
<1%
  • ed01-cms project ed01-cms
CVE-2020-18261
+2 in the same advisory: …18262 …18259
An arbitrary file upload vulnerability in the image upload function of ED01-CMS v1.0 allows attackers to execute arbitrary commands.

An arbitrary file upload vulnerability in the image upload function of ED01-CMS v1.0 allows attackers to execute arbitrary commands.

NVD description · AI analysis pending
9.8
group max
1% PoC
  • ed01-cms project ed01-cms