ZeroHour

Vulnerabilities

8 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2019-10842
Arbitrary code execution (via backdoor code) was discovered in bootstrap-sass 3.2.0.3, when downloaded from rubygems.org.

Arbitrary code execution (via backdoor code) was discovered in bootstrap-sass 3.2.0.3, when downloaded from rubygems.org. An unauthenticated attacker can craft the ___cfduid cookie value with base64 arbitrary code to be executed via eval(), which can be leveraged to execute arbitrary code on the target system. Note that there are three underscore characters in the cookie name. This is unrelated to the __cfduid cookie that is legitimately used by Cloudflare.

NVD description · AI analysis pending
9.85% PoC ×2
  • getbootstrap bootstrap-sass
CVE-2019-8331
In Bootstrap before 3.4.1 and 4.3.x before 4.3.1, XSS is possible in the tooltip or popover data-template attribute.

In Bootstrap before 3.4.1 and 4.3.x before 4.3.1, XSS is possible in the tooltip or popover data-template attribute.

NVD description · AI analysis pending
6.116%
  • getbootstrap bootstrap
  • getbootstrap big-ip access policy manager
  • getbootstrap big-ip advanced firewall manager
  • +1 more
CVE-2016-10735
+2 in the same advisory: …20677 …20676
In Bootstrap 3.x before 3.4.0 and 4.x-beta before 4.0.0-beta.2, XSS is possible in the data-target attribute, a different vulnerability than CVE-2018-14041.

In Bootstrap 3.x before 3.4.0 and 4.x-beta before 4.0.0-beta.2, XSS is possible in the data-target attribute, a different vulnerability than CVE-2018-14041.

NVD description · AI analysis pending
6.14% PoC
  • getbootstrap bootstrap
CVE-2018-14041
+1 in the same advisory: …14042
In Bootstrap before 4.1.2, XSS is possible in the data-target property of scrollspy.

In Bootstrap before 4.1.2, XSS is possible in the data-target property of scrollspy.

NVD description · AI analysis pending
6.14% PoC
  • getbootstrap bootstrap
CVE-2018-14040
In Bootstrap before 4.1.2, XSS is possible in the collapse data-parent attribute.

In Bootstrap before 4.1.2, XSS is possible in the collapse data-parent attribute.

NVD description · AI analysis pending
6.14% PoC
  • debian debian linux
  • debian bootstrap