ZeroHour

Vulnerabilities

5 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-41550
+1 in the same advisory: …41551
Leostream Connection Broker 9.0.40.17 allows administrator to upload and execute Perl code.

Leostream Connection Broker 9.0.40.17 allows administrator to upload and execute Perl code.

NVD description · AI analysis pending
7.2
group max
<1%
  • leostream connection broker
CVE-2021-38157
LeoStream Connection Broker 9.x before 9.0.34.3 allows Unauthenticated Reflected XSS via the /index.pl user parameter.

LeoStream Connection Broker 9.x before 9.0.34.3 allows Unauthenticated Reflected XSS via the /index.pl user parameter. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

NVD description · AI analysis pending
6.11% PoC
  • leostream connection broker
CVE-2020-26574
Leostream Connection Broker 8.2.x is affected by stored XSS.

Leostream Connection Broker 8.2.x is affected by stored XSS. An unauthenticated attacker can inject arbitrary JavaScript code via the webquery.pl User-Agent HTTP header. It is rendered by the admins the next time they log in. The JavaScript injected can be used to force the admin to upload a malicious Perl script that will be executed as root via libMisc::browser_client. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

NVD description · AI analysis pending
9.62% PoC
  • leostream connection broker
CVE-2018-18817
The Leostream Agent before Build 7.0.1.0 when used with Leostream Connection Broker 8.2.72 or earlier allows remote attackers to modify registry keys via the Le

The Leostream Agent before Build 7.0.1.0 when used with Leostream Connection Broker 8.2.72 or earlier allows remote attackers to modify registry keys via the Leostream Agent API.

NVD description · AI analysis pending
7.51%
  • leostream agent
  • leostream connection broker