ZeroHour

Vulnerabilities

6 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2017-7402
Pixie 1.0.4 allows remote authenticated users to upload and execute arbitrary PHP code via the POST data in an admin/index.php?s=publish&x=filemanager request f

Pixie 1.0.4 allows remote authenticated users to upload and execute arbitrary PHP code via the POST data in an admin/index.php?s=publish&x=filemanager request for a filename with a double extension, such as a .jpg.php file with Content-Type of image/jpeg.

NVD description · AI analysis pending
9.85% PoC
  • lucidcrew pixie
CVE-2017-7359
+4 in the same advisory: …7361 …7362 …7363 …7360
Pixie 1.0.4 allows an admin/index.php s=login&m= XSS attack.

Pixie 1.0.4 allows an admin/index.php s=login&m= XSS attack.

NVD description · AI analysis pending
6.11% PoC
  • lucidcrew pixie