ZeroHour

Vulnerabilities

2 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2019-25580
ownDMS 4.7 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through th

ownDMS 4.7 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the IMG parameter. Attackers can send GET requests to pdfstream.php, imagestream.php, or anyfilestream.php with crafted SQL payloads in the IMG parameter to extract sensitive database information including version and database names.

NVD description · AI analysis pending
8.8<1% PoC
  • owndms owndms
CVE-2018-18527
OwnTicket 2018-05-23 allows SQL Injection via the showTicketId or editTicketStatusId parameter.

OwnTicket 2018-05-23 allows SQL Injection via the showTicketId or editTicketStatusId parameter.

NVD description · AI analysis pending
9.82% PoC
  • owndms ownticket