ZeroHour

Vulnerabilities

6 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-35975
Absolute path traversal vulnerability in the Systematica SMTP Adapter component (up to v2.0.1.101) in Systematica Radius (up to v.3.9.256.777) allows remote att

Absolute path traversal vulnerability in the Systematica SMTP Adapter component (up to v2.0.1.101) in Systematica Radius (up to v.3.9.256.777) allows remote attackers to read arbitrary files via a full pathname in GET parameter "file" in URL. Also: affected components in same product - HTTP Adapter (up to v.1.8.0.15), MSSQL MessageBus Proxy (up to v.1.1.06), Financial Calculator (up to v.1.3.05), FIX Adapter (up to v.2.4.0.25)

NVD description · AI analysis pending
5.31% PoC
  • systematica financial calculator
  • systematica fix adapter
  • systematica http adapter
  • +1 more
CVE-2022-39838
Systematic FIX Adapter (ALFAFX) 2.4.0.25 13/09/2017 allows remote file inclusion via a UNC share pathname, and also allows absolute path traversal to local path

Systematic FIX Adapter (ALFAFX) 2.4.0.25 13/09/2017 allows remote file inclusion via a UNC share pathname, and also allows absolute path traversal to local pathnames.

NVD description · AI analysis pending
8.62% PoC
  • systematicalpha systematic fix adapter firmware
CVE-2019-18926
Systematic IRIS Standards Management (ISM) v2.1 SP1 89 is vulnerable to unauthenticated reflected Cross Site Scripting (XSS).

Systematic IRIS Standards Management (ISM) v2.1 SP1 89 is vulnerable to unauthenticated reflected Cross Site Scripting (XSS). A user input (related to dialog information) is reflected directly in the web page, allowing a malicious user to conduct a Cross Site Scripting attack against users of the application.

NVD description · AI analysis pending
6.1<1%
  • systematicinc iris standards management
CVE-2019-18925
+1 in the same advisory: …18924
Systematic IRIS WebForms 5.4 and its functionalities can be accessed and used without any form of authentication.

Systematic IRIS WebForms 5.4 and its functionalities can be accessed and used without any form of authentication.

NVD description · AI analysis pending
9.8
group max
1%
  • systematic iris webforms
CVE-2018-9115
Systematic SitaWare 6.4 SP2 does not validate input from other sources sufficiently.

Systematic SitaWare 6.4 SP2 does not validate input from other sources sufficiently. e.g., information utilizing the NVG interface. An attacker can freeze the Situational Layer, which means that the Situational Picture is no longer updated. Unfortunately, the user cannot notice until he tries to work with that layer.

NVD description · AI analysis pending
5.36% PoC ×2
  • systematicinc sitaware