ZeroHour

Vulnerabilities

6 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2020-22820
+2 in the same advisory: …22819 …22818
MKCMS V6.2 has SQL injection via the /ucenter/repass.php name parameter.

MKCMS V6.2 has SQL injection via the /ucenter/repass.php name parameter.

NVD description · AI analysis pending
9.8<1% PoC
  • mkcms project mkcms
CVE-2019-11332
MKCMS 5.0 allows remote attackers to take over arbitrary user accounts by posting a username and e-mail address to ucenter/repass.php, which triggers e-mail tra

MKCMS 5.0 allows remote attackers to take over arbitrary user accounts by posting a username and e-mail address to ucenter/repass.php, which triggers e-mail transmission with the password, as demonstrated by 123456.

NVD description · AI analysis pending
8.82% PoC
  • mkcms project mkcms
CVE-2019-11078
MKCMS V5.0 has a CSRF vulnerability to add a new admin user via the ucenter/userinfo.php URI.

MKCMS V5.0 has a CSRF vulnerability to add a new admin user via the ucenter/userinfo.php URI.

NVD description · AI analysis pending
8.8<1% PoC
  • mkcms project mkcms
CVE-2019-10707
MKCMS V5.0 has SQL injection via the bplay.php play parameter.

MKCMS V5.0 has SQL injection via the bplay.php play parameter.

NVD description · AI analysis pending
9.81% PoC
  • mkcms project mkcms