ZeroHour

Vulnerabilities

20 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2020-21252
Cross Site Request Forgery vulnerability in Neeke HongCMS 3.0.0 allows a remote attacker to execute arbitrary code and escalate privileges via the updateusers p

Cross Site Request Forgery vulnerability in Neeke HongCMS 3.0.0 allows a remote attacker to execute arbitrary code and escalate privileges via the updateusers parameter.

NVD description · AI analysis pending
8.8<1% PoC
  • hongcms project hongcms
CVE-2020-21643
Cross Site Scripting (XSS) vulnerability in HongCMS 3.0 allows attackers to run arbitrary code via the callback parameter to /ajax/myshop.

Cross Site Scripting (XSS) vulnerability in HongCMS 3.0 allows attackers to run arbitrary code via the callback parameter to /ajax/myshop.

NVD description · AI analysis pending
6.1<1% PoC
  • hongcms project hongcms
CVE-2022-32412
+1 in the same advisory: …32411
An issue in the /template/edit component of HongCMS v3.0 allows attackers to getshell.

An issue in the /template/edit component of HongCMS v3.0 allows attackers to getshell.

NVD description · AI analysis pending
7.2<1% PoC
  • hongcms project hongcms
CVE-2022-28523
HongCMS 3.0.0 allows arbitrary file deletion via the component /admin/index.php/template/ajax?action=delete.

HongCMS 3.0.0 allows arbitrary file deletion via the component /admin/index.php/template/ajax?action=delete.

NVD description · AI analysis pending
8.11% PoC
  • hongcms project hongcms
CVE-2020-21431
HongCMS v3.0 contains an arbitrary file read and write vulnerability in the component /admin/index.php/template/edit.

HongCMS v3.0 contains an arbitrary file read and write vulnerability in the component /admin/index.php/template/edit.

NVD description · AI analysis pending
6.5<1% PoC
  • hongcms project hongcms
CVE-2020-18178
Path Traversal in HongCMS v4.0.0 allows remote attackers to view, edit, and delete arbitrary files via a crafted POST request to the component "/hcms/admin/inde

Path Traversal in HongCMS v4.0.0 allows remote attackers to view, edit, and delete arbitrary files via a crafted POST request to the component "/hcms/admin/index.php/language/ajax."

NVD description · AI analysis pending
9.82% PoC
  • hongcms project hongcms
CVE-2019-17611
+4 in the same advisory: …17610 …17609 …17608 …17607
HongCMS 3.0.0 has XSS via the install/index.php tableprefix parameter.

HongCMS 3.0.0 has XSS via the install/index.php tableprefix parameter.

NVD description · AI analysis pending
6.11% PoC ×2
  • hongcms project hongcms
CVE-2019-16867
HongCMS 3.0.0 allows arbitrary file deletion via a ../ in the file parameter to admin/index.php/database/ajax?action=delete, a similar issue to CVE-2018-16774.

HongCMS 3.0.0 allows arbitrary file deletion via a ../ in the file parameter to admin/index.php/database/ajax?action=delete, a similar issue to CVE-2018-16774. (If the attacker deletes config.php and visits install/index.php, they can reinstall the product.)

NVD description · AI analysis pending
6.51% PoC
  • hongcms project hongcms
CVE-2019-8407
HongCMS 3.0.0 allows arbitrary file read and write operations via a ../ in the filename parameter to the admin/index.php/language/edit URI.

HongCMS 3.0.0 allows arbitrary file read and write operations via a ../ in the filename parameter to the admin/index.php/language/edit URI.

NVD description · AI analysis pending
6.51% PoC
  • hongcms project hongcms
CVE-2018-16774
HongCMS 3.0.0 allows arbitrary file deletion via a ../ in the file parameter to admin/index.php/language/ajax?action=delete.

HongCMS 3.0.0 allows arbitrary file deletion via a ../ in the file parameter to admin/index.php/language/ajax?action=delete.

NVD description · AI analysis pending
7.52% PoC
  • hongcms project hongcms
CVE-2018-13021
An issue was discovered in HongCMS 3.0.0.

An issue was discovered in HongCMS 3.0.0. There is an Arbitrary Script File Upload issue that can result in PHP code execution via the admin/index.php/template/upload URI.

NVD description · AI analysis pending
7.22% PoC
  • hongcms project hongcms
CVE-2018-12912
An issue wan discovered in admin\controllers\database.php in HongCMS 3.0.0.

An issue wan discovered in admin\controllers\database.php in HongCMS 3.0.0. There is a SQL Injection vulnerability via an admin/index.php/database/operate?dbaction=emptytable&tablename= URI.

NVD description · AI analysis pending
7.23% PoC
  • hongcms project hongcms
CVE-2018-12266
system\errors\404.php in HongCMS 3.0.0 has XSS via crafted input that triggers a 404 HTTP status code.

system\errors\404.php in HongCMS 3.0.0 has XSS via crafted input that triggers a 404 HTTP status code.

NVD description · AI analysis pending
6.1<1% PoC
  • hongcms project hongcms
CVE-2018-10422
An issue was discovered in HongCMS 3.0.0.

An issue was discovered in HongCMS 3.0.0. The post news feature has Stored XSS via the content field.

NVD description · AI analysis pending
4.8<1% PoC
  • hongcms project hongcms
CVE-2018-10265
An issue was discovered in HongCMS v3.0.0.

An issue was discovered in HongCMS v3.0.0. There is a CSRF vulnerability that can add an administrator account via the admin/index.php/users/save URI.

NVD description · AI analysis pending
8.8<1%
  • hongcms project hongcms