ZeroHour

Vulnerabilities

14 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-44098
EGavilan Media Expense-Management-System 1.0 is vulnerable to SQL Injection via /expense_action.php.

EGavilan Media Expense-Management-System 1.0 is vulnerable to SQL Injection via /expense_action.php. This allows a remote attacker to compromise Application SQL database.

NVD description · AI analysis pending
9.81% PoC
  • egavilanmedia expense management system
CVE-2021-44096
EGavilan Media User-Registration-and-Login-System-With-Admin-Panel 1.0 is vulnerable to SQL Injection via profile_action - update_user.

EGavilan Media User-Registration-and-Login-System-With-Admin-Panel 1.0 is vulnerable to SQL Injection via profile_action - update_user. This allows a remote attacker to compromise Application SQL database.

NVD description · AI analysis pending
9.81% PoC
  • egavilanmedia user registration and login system with admin panel
CVE-2020-36115
Stored Cross Site Scripting (XSS) vulnerability in EGavilan Media CRUD Operation with PHP, MySQL, Bootstrap, and Dompdf via First Name or Last Name parameter in

Stored Cross Site Scripting (XSS) vulnerability in EGavilan Media CRUD Operation with PHP, MySQL, Bootstrap, and Dompdf via First Name or Last Name parameter in the 'Add New Record Feature'.

NVD description · AI analysis pending
5.4<1% PoC
  • egavilanmedia phpcrud
CVE-2020-35263
EgavilanMedia User Registration & Login System 1.0 is affected by SQL injection to the admin panel, which may allow arbitrary code execution.

EgavilanMedia User Registration & Login System 1.0 is affected by SQL injection to the admin panel, which may allow arbitrary code execution.

NVD description · AI analysis pending
9.82% PoC
  • egavilanmedia user registration and login system with admin panel
CVE-2020-29228
+2 in the same advisory: …29230 …29231
EGavilanMedia User Registration and Login System With Admin Panel 1.0 is affected by SQL injection in the User Login Page.

EGavilanMedia User Registration and Login System With Admin Panel 1.0 is affected by SQL injection in the User Login Page.

NVD description · AI analysis pending
7.5
group max
1% PoC
  • egavilanmedia user registration and login system with admin panel
CVE-2020-29474
EGavilan Media EGM Address Book 1.0 contains a SQL injection vulnerability.

EGavilan Media EGM Address Book 1.0 contains a SQL injection vulnerability. An attacker can gain Admin Panel access using malicious SQL injection queries to perform remote arbitrary code execution.

NVD description · AI analysis pending
9.84% PoC ×2
  • egavilanmedia egm address book
CVE-2020-29472
EGavilan Media Under Construction page with cPanel 1.0 contains a SQL injection vulnerability.

EGavilan Media Under Construction page with cPanel 1.0 contains a SQL injection vulnerability. An attacker can gain Admin Panel access using malicious SQL injection queries to perform remote arbitrary code execution.

NVD description · AI analysis pending
9.84% PoC ×2
  • egavilanmedia under construction page with cpanel
CVE-2020-35252
Cross Site Scripting (XSS) vulnerability via the 'Full Name' parameter in the User Registration section of User Registration & Login System with Admin Panel 1.0

Cross Site Scripting (XSS) vulnerability via the 'Full Name' parameter in the User Registration section of User Registration & Login System with Admin Panel 1.0.

NVD description · AI analysis pending
6.1<1% PoC
  • egavilanmedia user registration and login system with admin panel
CVE-2020-35276
EgavilanMedia ECM Address Book 1.0 is affected by SQL injection.

EgavilanMedia ECM Address Book 1.0 is affected by SQL injection. An attacker can bypass the Admin Login panel through SQLi and get Admin access and add or remove any user.

NVD description · AI analysis pending
9.82% PoC
  • egavilanmedia ecm address book
CVE-2020-35273
EgavilanMedia User Registration & Login System with Admin Panel 1.0 is affected by Cross Site Request Forgery (CSRF) to remotely gain privileges in the User Pro

EgavilanMedia User Registration & Login System with Admin Panel 1.0 is affected by Cross Site Request Forgery (CSRF) to remotely gain privileges in the User Profile panel. An attacker can update any user's account.

NVD description · AI analysis pending
8.0<1% PoC
  • egavilanmedia user registration \& login system with admin panel
CVE-2020-35396
EGavilan Barcodes generator 1.0 is affected by:

EGavilan Barcodes generator 1.0 is affected by: Cross Site Scripting (XSS) via the index.php. An Attacker is able to inject the XSS payload in the web application each time a user visits the website.

NVD description · AI analysis pending
6.11% PoC ×2
  • egavilanmedia barcodes generator
CVE-2020-35395
XSS in the Add Expense Component of EGavilan Media Expense Management System 1.0 allows an attacker to permanently store malicious JavaScript code via the 'desc

XSS in the Add Expense Component of EGavilan Media Expense Management System 1.0 allows an attacker to permanently store malicious JavaScript code via the 'description' field

NVD description · AI analysis pending
6.1<1% PoC ×2
  • egavilanmedia expense management system