ZeroHour

Vulnerabilities

6 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-33445
An issue in hisiphp v2.0.111 allows a remote attacker to execute arbitrary code via a crafted script to the SystemPlugins::mkInfo parameter in the SystemPlugins

An issue in hisiphp v2.0.111 allows a remote attacker to execute arbitrary code via a crafted script to the SystemPlugins::mkInfo parameter in the SystemPlugins.php component.

NVD description · AI analysis pending
9.81% PoC ×2
  • hisiphp hisiphp
CVE-2020-28062
An Access Control vulnerability exists in HisiPHP 2.0.11 via special packets that are constructed in $files = Dir::getList($decompath.

An Access Control vulnerability exists in HisiPHP 2.0.11 via special packets that are constructed in $files = Dir::getList($decompath. '/ Upload/Plugins /, which could let a remote malicious user execute arbitrary code.

NVD description · AI analysis pending
7.23% PoC
  • hisiphp hisiphp
CVE-2020-21130
Cross Site Scripting (XSS) vulnerability in HisiPHP 2.0.8 via the group name in addgroup.html.

Cross Site Scripting (XSS) vulnerability in HisiPHP 2.0.8 via the group name in addgroup.html.

NVD description · AI analysis pending
6.1<1% PoC
  • hisiphp hisiphp
CVE-2019-1010193
hisiphp 1.0.8 is affected by:

hisiphp 1.0.8 is affected by: Cross Site Scripting (XSS).

NVD description · AI analysis pending
6.1<1% PoC
  • hisiphp hisiphp
CVE-2018-17826
+1 in the same advisory: …17827
HisiPHP 1.0.8 allows CSRF via admin.php/admin/user/adduser.html to add an administrator account.

HisiPHP 1.0.8 allows CSRF via admin.php/admin/user/adduser.html to add an administrator account. The attacker can then use that account to execute arbitrary PHP code by leveraging app/common/model/AdminAnnex.php to add .php to the default list of allowable file-upload types (.jpg, .png, .gif, .jpeg, and .ico).

NVD description · AI analysis pending
8.8
group max
<1% PoC
  • hisiphp hisiphp