ZeroHour

Vulnerabilities

11 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-5407
+2 in the same advisory: …5408 …5409
A vulnerability in RhinOS 3.0-1190 could allow PHP code injection through the "search" parameter in /portal/search.htm.

A vulnerability in RhinOS 3.0-1190 could allow PHP code injection through the "search" parameter in /portal/search.htm. This vulnerability could allow a remote attacker to perform a reverse shell on the remote system, compromising the entire infrastructure.

NVD description · AI analysis pending
9.8
group max
<1%
  • saltos rhinos
CVE-2019-19459
+3 in the same advisory: …19458 …19460 …19457
An issue was discovered in SALTO ProAccess SPACE 5.4.3.0.

An issue was discovered in SALTO ProAccess SPACE 5.4.3.0. An attacker can write arbitrary content to arbitrary files, as demonstrated by CVE-2019-19458 files under the web root, or .bat files that will be used with auto start. This allows an attacker to execute arbitrary commands on the server.

NVD description · AI analysis pending
9.8
group max
4% PoC
  • saltosystem proaccess space
CVE-2018-18762
SaltOS 3.1 r8126 contains a database download vulnerability.

SaltOS 3.1 r8126 contains a database download vulnerability.

NVD description · AI analysis pending
6.56% PoC ×2
  • saltos saltos
CVE-2018-18761
+1 in the same advisory: …18763
SaltOS 3.1 r8126 allows action=login&querystring=&user=[SQL] SQL Injection.

SaltOS 3.1 r8126 allows action=login&querystring=&user=[SQL] SQL Injection.

NVD description · AI analysis pending
9.816% PoC
  • saltos saltos
CVE-2018-18760
RhinOS 3.0 build 1190 allows CSRF.

RhinOS 3.0 build 1190 allows CSRF.

NVD description · AI analysis pending
6.53% PoC ×2
  • saltos rhinos