ZeroHour

Vulnerabilities

3 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-26551
+2 in the same advisory: …26550 …26549
An issue was discovered in SmartFoxServer 2.17.0.

An issue was discovered in SmartFoxServer 2.17.0. An attacker can execute arbitrary Python code, and bypass the javashell.py protection mechanism, by creating /config/ConsoleModuleUnlock.txt and editing /config/admin/admintool.xml to enable the Console module.

NVD description · AI analysis pending
8.8
group max
3% PoC ×2
  • smartfoxserver smartfoxserver