ZeroHour

Vulnerabilities

28 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2020-29168
SQL Injection vulnerability in Projectworlds Online Doctor Appointment Booking System, allows attackers to gain sensitive information via the q parameter to the

SQL Injection vulnerability in Projectworlds Online Doctor Appointment Booking System, allows attackers to gain sensitive information via the q parameter to the getuser.php endpoint.

NVD description · AI analysis pending
9.81% PoC
  • online doctor appointment booking system php and mysql project online doctor appointment booking system php and mysql
CVE-2021-3779
A malicious MySQL server can request local file content from a client using ruby-mysql prior to version 2.10.0 without explicit authorization from the user.

A malicious MySQL server can request local file content from a client using ruby-mysql prior to version 2.10.0 without explicit authorization from the user. This issue was resolved in version 2.10.0 and later.

NVD description · AI analysis pending
6.51% PoC
  • ruby-mysql project ruby-mysql
CVE-2022-30478
+1 in the same advisory: …30482
Ecommerce-project-with-php-and-mysqli-Fruits-Bazar 1.0 is vulnerable to SQL Injection in \search_product.php via the keyword parameters.

Ecommerce-project-with-php-and-mysqli-Fruits-Bazar 1.0 is vulnerable to SQL Injection in \search_product.php via the keyword parameters.

NVD description · AI analysis pending
9.8
group max
2% PoC
  • ecommerce-project-with-php-and-mysqli-fruits-bazar project ecommerce-project-with-php-and-mysqli-fruits-bazar
CVE-2022-28102
A cross-site scripting (XSS) vulnerability in PHP MySQL Admin Panel Generator v1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload

A cross-site scripting (XSS) vulnerability in PHP MySQL Admin Panel Generator v1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected at /edit-db.php.

NVD description · AI analysis pending
5.4<1% PoC
  • php mysql admin panel generator project php mysql admin panel generator
CVE-2020-29283
An SQL injection vulnerability was discovered in Online Doctor Appointment Booking System PHP and Mysql via the q parameter to getuser.php.

An SQL injection vulnerability was discovered in Online Doctor Appointment Booking System PHP and Mysql via the q parameter to getuser.php.

NVD description · AI analysis pending
9.81% PoC
  • online doctor appointment booking system php and mysql project online doctor appointment booking system php and mysql
CVE-2020-28688
+1 in the same advisory: …28687
The add artwork functionality in ARTWORKS GALLERY IN PHP, CSS, JAVASCRIPT, AND MYSQL 1.0 allows remote attackers to upload arbitrary files.

The add artwork functionality in ARTWORKS GALLERY IN PHP, CSS, JAVASCRIPT, AND MYSQL 1.0 allows remote attackers to upload arbitrary files.

NVD description · AI analysis pending
8.812% PoC
  • artworks gallery in php\, css\, javascript\, and mysql project artworks gallery in php\, css\, javascript\, and mysql
CVE-2019-14939
An issue was discovered in the mysql (aka mysqljs) module 2.17.1 for Node.js.

An issue was discovered in the mysql (aka mysqljs) module 2.17.1 for Node.js. The LOAD DATA LOCAL INFILE option is open by default.

NVD description · AI analysis pending
5.5<1%
  • mysql project mysql
CVE-2018-3754
Node.js third-party module query-mysql versions 0.0.0, 0.0.1, and 0.0.2 are vulnerable to an SQL injection vulnerability due to lack of user input sanitization.

Node.js third-party module query-mysql versions 0.0.0, 0.0.1, and 0.0.2 are vulnerable to an SQL injection vulnerability due to lack of user input sanitization. This may allow an attacker to run arbitrary SQL queries when fetching data from database.

NVD description · AI analysis pending
8.81% PoC
  • query-mysql project query-mysql
CVE-2017-16047
mysqljs was a malicious module published with the intent to hijack environment variables.

mysqljs was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

NVD description · AI analysis pending
7.51%
  • mysqljs project mysqljs
CVE-2017-14475
In the MMM::Agent::Helpers::Network::add_ip function in MySQL Multi-Master Replication Manager (MMM) mmm_agentd 2.2.1 (for Linux), a specially crafted MMM proto

In the MMM::Agent::Helpers::Network::add_ip function in MySQL Multi-Master Replication Manager (MMM) mmm_agentd 2.2.1 (for Linux), a specially crafted MMM protocol message can cause a shell command injection resulting in arbitrary command execution with the privileges of the mmm\_agentd process. An attacker that can initiate a TCP session with mmm\_agentd can trigger this vulnerability.

NVD description · AI analysis pending
9.86% PoC
  • mysql-mmm mysql multi-master replication manager
CVE-2018-10757
CSP MySQL User Manager 2.3.1 allows SQL injection, and resultant Authentication Bypass, via a crafted username during a login attempt.

CSP MySQL User Manager 2.3.1 allows SQL injection, and resultant Authentication Bypass, via a crafted username during a login attempt.

NVD description · AI analysis pending
9.85% PoC ×2
  • csp mysql user manager project csp mysql user manager
CVE-2017-15945
The installation scripts in the Gentoo dev-db/mysql, dev-db/mariadb, dev-db/percona-server, dev-db/mysql-cluster, and dev-db/mariadb-galera packages before 2017

The installation scripts in the Gentoo dev-db/mysql, dev-db/mariadb, dev-db/percona-server, dev-db/mysql-cluster, and dev-db/mariadb-galera packages before 2017-09-29 have chown calls for user-writable directory trees, which allows local users to gain privileges by leveraging access to the mysql account for creation of a link.

NVD description · AI analysis pending
7.8<1%
  • mariadb mariadb
  • mariadb mysql
CVE-2017-1000012
MySQL Dumper version 1.24 is vulnerable to stored XSS when displaying the data in the database to the user

MySQL Dumper version 1.24 is vulnerable to stored XSS when displaying the data in the database to the user

NVD description · AI analysis pending
6.1<1%
  • mysqldumper mysqldumper
CVE-2017-10788
+1 in the same advisory: …10789
The DBD::mysql module through 4.043 for Perl allows remote attackers to cause a denial of service (use-after-free and application crash) or possibly have unspec

The DBD::mysql module through 4.043 for Perl allows remote attackers to cause a denial of service (use-after-free and application crash) or possibly have unspecified other impact by triggering (1) certain error responses from a MySQL server or (2) a loss of a network connection to a MySQL server. The use-after-free defect was introduced by relying on incorrect Oracle mysql_stmt_close documentation and code examples.

NVD description · AI analysis pending
9.8
group max
5%
  • dbd-mysql project dbd-mysql
CVE-2017-9602
KBVault Mysql Free Knowledge Base application package 0.16a comes with a FileExplorer/Explorer.aspx?id=/Uploads file-management component.

KBVault Mysql Free Knowledge Base application package 0.16a comes with a FileExplorer/Explorer.aspx?id=/Uploads file-management component. An unauthenticated user can access the file upload and deletion functionality. Through this functionality, a user can upload an ASPX script to Uploads/Documents/ to run any arbitrary code.

NVD description · AI analysis pending
9.84%
  • kbvault mysql project kbvault mysql
CVE-2016-1249
The DBD::mysql module before 4.039 for Perl, when using server-side prepared statement support, allows attackers to cause a denial of service (out-of-bounds rea

The DBD::mysql module before 4.039 for Perl, when using server-side prepared statement support, allows attackers to cause a denial of service (out-of-bounds read) via vectors involving an unaligned number of placeholders in WHERE condition and output fields in SELECT expression.

NVD description · AI analysis pending
5.92%
  • dbd-mysql project dbd-mysql
CVE-2016-1251
There is a vulnerability of type use-after-free affecting DBD::mysql (aka DBD-mysql or the Database Interface (DBI) MySQL driver for Perl) 3.x and 4.x before 4.

There is a vulnerability of type use-after-free affecting DBD::mysql (aka DBD-mysql or the Database Interface (DBI) MySQL driver for Perl) 3.x and 4.x before 4.041 when used with mysql_server_prepare=1.

NVD description · AI analysis pending
8.13%
  • dbd-mysql project dbd-mysql
CVE-2016-1246
Buffer overflow in the DBD::mysql module before 4.037 for Perl allows context-dependent attackers to cause a denial of service (crash) via vectors related to an

Buffer overflow in the DBD::mysql module before 4.037 for Perl allows context-dependent attackers to cause a denial of service (crash) via vectors related to an error message.

NVD description · AI analysis pending
7.54%
  • dbd-mysql project dbd-mysql
  • dbd-mysql project debian linux