ZeroHour

Vulnerabilities

22 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2020-21400
SQL injection vulnerability in gaozhifeng PHPMyWind v.5.6 allows a remote attacker to execute arbitrary code via the id variable in the modify function.

SQL injection vulnerability in gaozhifeng PHPMyWind v.5.6 allows a remote attacker to execute arbitrary code via the id variable in the modify function.

NVD description · AI analysis pending
7.21% PoC
  • phpmywind phpmywind
CVE-2020-21060
SQL injection vulnerability found in PHPMyWind v.5.6 allows a remote attacker to gain privileges via the delete function of the administrator management page.

SQL injection vulnerability found in PHPMyWind v.5.6 allows a remote attacker to gain privileges via the delete function of the administrator management page.

NVD description · AI analysis pending
8.8<1% PoC
  • phpmywind phpmywind
CVE-2020-19964
A Cross Site Request Forgery (CSRF) vulnerability was discovered in PHPMyWind 5.6 which allows attackers to create a new administrator account without authentic

A Cross Site Request Forgery (CSRF) vulnerability was discovered in PHPMyWind 5.6 which allows attackers to create a new administrator account without authentication.

NVD description · AI analysis pending
6.5<1% PoC
  • phpmywind phpmywind
CVE-2021-39503
PHPMyWind 5.6 is vulnerable to Remote Code Execution.

PHPMyWind 5.6 is vulnerable to Remote Code Execution. Becase input is filtered without " , ?, =, `,...." In WriteConfig() function, an attacker can inject php code to /include/config.cache.php file.

NVD description · AI analysis pending
7.23% PoC ×2
  • phpmywind phpmywind
CVE-2020-18885
+1 in the same advisory: …18886
Command Injection in PHPMyWind v5.6 allows remote attackers to execute arbitrary code via the "text color" field of the component '/admin/web_config.php'.

Command Injection in PHPMyWind v5.6 allows remote attackers to execute arbitrary code via the "text color" field of the component '/admin/web_config.php'.

NVD description · AI analysis pending
7.24% PoC
  • phpmywind phpmywind
CVE-2020-18230
+1 in the same advisory: …18229
Cross Site Scripting (XSS) in PHPMyWind v5.5 allows remote attackers to execute arbitrary code by injecting scripts into the parameter "$cfg_switchshow" of comp

Cross Site Scripting (XSS) in PHPMyWind v5.5 allows remote attackers to execute arbitrary code by injecting scripts into the parameter "$cfg_switchshow" of component " /admin/web_config.php".

NVD description · AI analysis pending
4.8<1% PoC
  • phpmywind phpmywind
CVE-2019-16703
+1 in the same advisory: …16704
admin/infolist_add.php in PHPMyWind 5.6 has stored XSS.

admin/infolist_add.php in PHPMyWind 5.6 has stored XSS.

NVD description · AI analysis pending
6.1
group max
<1% PoC
  • phpmywind phpmywind
CVE-2019-7661
+1 in the same advisory: …7660
An issue was discovered in PHPMyWind 5.5.

An issue was discovered in PHPMyWind 5.5. The method parameter of the data/api/oauth/connect.php page has a reflected Cross-site Scripting (XSS) vulnerability.

NVD description · AI analysis pending
6.1<1% PoC
  • phpmywind phpmywind
CVE-2019-8435
admin/default.php in PHPMyWind v5.5 has XSS via an HTTP Host header.

admin/default.php in PHPMyWind v5.5 has XSS via an HTTP Host header.

NVD description · AI analysis pending
4.8<1% PoC
  • phpmywind phpmywind
CVE-2019-7402
+1 in the same advisory: …7403
An issue was discovered in PHPMyWind 5.5.

An issue was discovered in PHPMyWind 5.5. The GetQQ function in include/func.class.php allows XSS via the cfg_qqcode parameter. This can be exploited via CSRF.

NVD description · AI analysis pending
6.1
group max
<1% PoC
  • phpmywind phpmywind
CVE-2018-17134
+4 in the same advisory: …17133 …17132 …17131 …17130
admin/web_config.php in PHPMyWind 5.5 allows Admin users to execute arbitrary code via the cfg_author field in conjunction with a crafted cfg_webpath field.

admin/web_config.php in PHPMyWind 5.5 allows Admin users to execute arbitrary code via the cfg_author field in conjunction with a crafted cfg_webpath field.

NVD description · AI analysis pending
7.2
group max
2% PoC
  • phpmywind phpmywind
CVE-2018-11487
PHPMyWind 5.5 has XSS via the cid parameter to newsshow.php, or the query string to news.php or about.php.

PHPMyWind 5.5 has XSS via the cid parameter to newsshow.php, or the query string to news.php or about.php.

NVD description · AI analysis pending
6.1<1%
  • phpmywind phpmywind
CVE-2017-12984
PHPMyWind 5.3 has XSS in shoppingcart.php, related to message.php, admin/message.php, and admin/message_update.php.

PHPMyWind 5.3 has XSS in shoppingcart.php, related to message.php, admin/message.php, and admin/message_update.php.

NVD description · AI analysis pending
6.12%
  • phpmywind phpmywind