ZeroHour

Vulnerabilities

30 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-46887
+3 in the same advisory: …46888 …46889 …46890
Multiple SQL injection vulnerabilities in NexusPHP before 1.7.33 allow remote attackers to execute arbitrary SQL commands via the conuser[] parameter in takecon

Multiple SQL injection vulnerabilities in NexusPHP before 1.7.33 allow remote attackers to execute arbitrary SQL commands via the conuser[] parameter in takeconfirm.php; the delcheater parameter in cheaterbox.php; or the usernw parameter in nowarn.php.

NVD description · AI analysis pending
9.8
group max
19% PoC
  • nexusphp nexusphp
CVE-2020-24770
+2 in the same advisory: …24769 …24771
SQL injection vulnerability in modrules.php in NexusPHP 1.5 allows remote attackers to execute arbitrary SQL commands via the id parameter.

SQL injection vulnerability in modrules.php in NexusPHP 1.5 allows remote attackers to execute arbitrary SQL commands via the id parameter.

NVD description · AI analysis pending
9.8
group max
2% PoC
  • nexusphp nexusphp
CVE-2017-15305
XSS exists in NexusPHP 1.5 via the keyword parameter to messages.php.

XSS exists in NexusPHP 1.5 via the keyword parameter to messages.php.

NVD description · AI analysis pending
6.1<1% PoC ×2
  • nexusphp project nexusphp
CVE-2017-12792
Multiple cross-site request forgery (CSRF) vulnerabilities in NexusPHP 1.5 allow remote attackers to hijack the authentication of administrators for requests th

Multiple cross-site request forgery (CSRF) vulnerabilities in NexusPHP 1.5 allow remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the (1) linkname, (2) url, or (3) title parameter in an add action to linksmanage.php.

NVD description · AI analysis pending
6.11% PoC
  • nexusphp project nexusphp
CVE-2017-14534
Cross Site Scripting (XSS) exists in NexusPHP 1.5.beta5.20120707 via the PATH_INFO to location.php, related to PHP_SELF.

Cross Site Scripting (XSS) exists in NexusPHP 1.5.beta5.20120707 via the PATH_INFO to location.php, related to PHP_SELF.

NVD description · AI analysis pending
6.1<1% PoC
  • nexusphp project nexusphp
CVE-2017-14512
NexusPHP 1.5.beta5.20120707 has SQL Injection in forummanage.php via the sort parameter in an editforum action, a different vulnerability than CVE-2017-12981.

NexusPHP 1.5.beta5.20120707 has SQL Injection in forummanage.php via the sort parameter in an editforum action, a different vulnerability than CVE-2017-12981.

NVD description · AI analysis pending
9.81% PoC
  • nexusphp project nexusphp
CVE-2017-14347
NexusPHP 1.5.beta5.20120707 has XSS in the returnto parameter to fun.php in a delete action.

NexusPHP 1.5.beta5.20120707 has XSS in the returnto parameter to fun.php in a delete action.

NVD description · AI analysis pending
6.1<1% PoC
  • nexusphp project nexusphp
CVE-2017-12838
+1 in the same advisory: …12906
Cross-site request forgery (CSRF) vulnerability in NexusPHP 1.5 allows remote attackers to hijack the authentication of users for requests that (1) send manas v

Cross-site request forgery (CSRF) vulnerability in NexusPHP 1.5 allows remote attackers to hijack the authentication of users for requests that (1) send manas via a request to mybonus.php or (2) add administrators via unspecified vectors.

NVD description · AI analysis pending
8.8
group max
<1% PoC
  • nexusphp project nexusphp
CVE-2017-14069
+2 in the same advisory: …14076 …14070
SQL Injection exists in NexusPHP 1.5.beta5.20120707 via the usernw array parameter to nowarn.php.

SQL Injection exists in NexusPHP 1.5.beta5.20120707 via the usernw array parameter to nowarn.php.

NVD description · AI analysis pending
9.8
group max
1% PoC
  • nexusphp nexusphp
CVE-2017-13669
+1 in the same advisory: …12679
SQL Injection exists in NexusPHP 1.5.beta5.20120707 via the setanswered parameter to staffbox.php.

SQL Injection exists in NexusPHP 1.5.beta5.20120707 via the setanswered parameter to staffbox.php.

NVD description · AI analysis pending
9.81% PoC
  • nexusphp nexusphp
CVE-2017-12981
NexusPHP 1.5.beta5.20120707 has SQL Injection in forummanage.php via the sort parameter in an addforum action.

NexusPHP 1.5.beta5.20120707 has SQL Injection in forummanage.php via the sort parameter in an addforum action.

NVD description · AI analysis pending
9.81% PoC
  • nexusphp nexusphp
CVE-2017-12776
+1 in the same advisory: …12680
SQL injection vulnerability in reports.php in NexusPHP 1.5 allows remote attackers to execute arbitrary SQL commands via the delreport parameter.

SQL injection vulnerability in reports.php in NexusPHP 1.5 allows remote attackers to execute arbitrary SQL commands via the delreport parameter.

NVD description · AI analysis pending
9.8
group max
1% PoC
  • nexusphp project nexusphp
CVE-2017-12909
+3 in the same advisory: …12910 …12908 …12907
SQL injection vulnerability in modtask.php in NexusPHP 1.5 allows remote attackers to execute arbitrary SQL commands via the userid parameter.

SQL injection vulnerability in modtask.php in NexusPHP 1.5 allows remote attackers to execute arbitrary SQL commands via the userid parameter.

NVD description · AI analysis pending
9.8
group max
1% PoC
  • nexusphp project nexusphp
CVE-2017-12798
Cross-Site Scripting (XSS) exists in NexusPHP version v1.5 via the q parameter to searchsuggest.php.

Cross-Site Scripting (XSS) exists in NexusPHP version v1.5 via the q parameter to searchsuggest.php.

NVD description · AI analysis pending
6.1<1% PoC
  • nexusphp project nexusphp
CVE-2017-12777
Cross-Site Scripting (XSS) exists in NexusPHP version v1.5 via some parameter to usersearch.php.

Cross-Site Scripting (XSS) exists in NexusPHP version v1.5 via some parameter to usersearch.php.

NVD description · AI analysis pending
6.1<1%
  • nexusphp project nexusphp
CVE-2017-12655
Cross-Site Scripting (XSS) exists in NexusPHP version v1.5 via the query parameter to log.php in a dailylog action.

Cross-Site Scripting (XSS) exists in NexusPHP version v1.5 via the query parameter to log.php in a dailylog action.

NVD description · AI analysis pending
6.1<1% PoC
  • nexusphp project nexusphp
CVE-2017-11651
NexusPHP V1.5 has XSS via a javascript:

NexusPHP V1.5 has XSS via a javascript: or data: URL in a UBBCode url tag.

NVD description · AI analysis pending
6.1<1% PoC
  • nexusphp nexusphp