ZeroHour

Vulnerabilities

8 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2020-28461
This affects the package js-ini before 1.3.0.

This affects the package js-ini before 1.3.0. If an attacker submits a malicious INI file to an application that parses it with parse , they will pollute the prototype on the application. This can be exploited further depending on the context.

NVD description · AI analysis pending
9.81% PoC
  • js-ini project js-ini
CVE-2020-28441
This affects the package conf-cfg-ini before 1.2.2.

This affects the package conf-cfg-ini before 1.2.2. If an attacker submits a malicious INI file to an application that parses it with decode, they will pollute the prototype on the application. This can be exploited further depending on the context.

NVD description · AI analysis pending
9.81% PoC
  • conf-cfg-ini project conf-cfg-ini
CVE-2020-18999
+1 in the same advisory: …18998
Cross Site Scripting (XSS) in Blog_mini v1.0 allows remote attackers to execute arbitrary code via the component '/admin/submit-articles'.

Cross Site Scripting (XSS) in Blog_mini v1.0 allows remote attackers to execute arbitrary code via the component '/admin/submit-articles'.

NVD description · AI analysis pending
6.11% PoC
  • blog mini project blog mini
CVE-2020-28448
+1 in the same advisory: …28460
This affects the package multi-ini before 2.1.1.

This affects the package multi-ini before 2.1.1. It is possible to pollute an object's prototype by specifying the proto object as part of an array.

NVD description · AI analysis pending
9.8
group max
1% PoC ×2
  • multi-ini project multi-ini
CVE-2020-7788
This affects the package ini before 1.3.6.

This affects the package ini before 1.3.6. If an attacker submits a malicious INI file to an application that parses it with ini.parse, they will pollute the prototype on the application. This can be exploited further depending on the context.

NVD description · AI analysis pending
9.84% PoC
  • ini project ini
  • ini project debian linux
CVE-2019-9765
In Blog_mini 1.0, XSS exists via the author name of a comment reply in the app/main/views.py articleDetails() function, related to app/templates/_article_commen

In Blog_mini 1.0, XSS exists via the author name of a comment reply in the app/main/views.py articleDetails() function, related to app/templates/_article_comments.html.

NVD description · AI analysis pending
6.1<1% PoC
  • blog mini project blog mini