ZeroHour

Vulnerabilities

4 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2018-18552
+1 in the same advisory: …18551
ServersCheck Monitoring Software through 14.3.3 allows local users to cause a denial of service (menu functionality loss) by creating an LNK file that points to

ServersCheck Monitoring Software through 14.3.3 allows local users to cause a denial of service (menu functionality loss) by creating an LNK file that points to a second LNK file, if this second LNK file is associated with a Start menu. Ultimately, this behavior comes from a Directory Traversal bug (via the sensor_details.html id parameter) that allows creating empty files in arbitrary directories.

NVD description · AI analysis pending
6.5
group max
3% PoC ×2
  • serverscheck monitoring software
CVE-2018-18550
ServersCheck Monitoring Software before 14.3.4 allows SQL Injection by an authenticated user.

ServersCheck Monitoring Software before 14.3.4 allows SQL Injection by an authenticated user.

NVD description · AI analysis pending
8.8<1%
  • serverscheck serverscheck
CVE-2017-17832
ServersCheck Monitoring Software before 14.2.3 is prone to a cross-site scripting vulnerability as user supplied-data is not validated/sanitized when passed in

ServersCheck Monitoring Software before 14.2.3 is prone to a cross-site scripting vulnerability as user supplied-data is not validated/sanitized when passed in the settings_SMS_ALERT_TYPE parameter, and JavaScript can be executed on settings-save.html (the Settings - SMS Alerts page).

NVD description · AI analysis pending
5.4<1% PoC
  • serverscheck monitoring software