ZeroHour

Vulnerabilities

4 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-24677
+1 in the same advisory: …24676
Admin.php in HYBBS2 through 2.3.2 allows remote code execution because it writes plugin-related configuration information to conf.php.

Admin.php in HYBBS2 through 2.3.2 allows remote code execution because it writes plugin-related configuration information to conf.php.

NVD description · AI analysis pending
9.8
group max
2% PoC
  • hyphp hybbs2
CVE-2019-10644
An issue was discovered in HYBBS 2.2.

An issue was discovered in HYBBS 2.2. /?admin/user.html has a CSRF vulnerability that can add an administrator account.

NVD description · AI analysis pending
8.8<1% PoC
  • hyphp hybbs
CVE-2018-14499
An issue was found in HYBBS through 2016-03-08.

An issue was found in HYBBS through 2016-03-08. There is an XSS vulnerablity via an article title to post.html.

NVD description · AI analysis pending
6.1<1%
  • hyphp hybbs