ZeroHour

Vulnerabilities

5 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2020-17363
USVN (aka User-friendly SVN) before 1.0.9 allows remote code execution via shell metacharacters in the number_start or number_end parameter to LastHundredReques

USVN (aka User-friendly SVN) before 1.0.9 allows remote code execution via shell metacharacters in the number_start or number_end parameter to LastHundredRequest (aka lasthundredrequestAction) in the Timeline module. NOTE: this may overlap CVE-2020-25069.

NVD description · AI analysis pending
9.94% PoC
  • usvn usvn
CVE-2020-25069
+1 in the same advisory: …25070
USVN (aka User-friendly SVN) before 1.0.10 allows attackers to execute arbitrary code in the commit view.

USVN (aka User-friendly SVN) before 1.0.10 allows attackers to execute arbitrary code in the commit view.

NVD description · AI analysis pending
9.8
group max
2%
  • usvn usvn
CVE-2020-17364
USVN (aka User-friendly SVN) before 1.0.9 allows XSS via SVN logs.

USVN (aka User-friendly SVN) before 1.0.9 allows XSS via SVN logs.

NVD description · AI analysis pending
6.1<1%
  • usvn user-friendly svn
CVE-2018-0695
Cross-site scripting vulnerability in User-friendly SVN (USVN) Version 1.0.7 and earlier allows remote attackers to inject arbitrary web script or HTML via unsp

Cross-site scripting vulnerability in User-friendly SVN (USVN) Version 1.0.7 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

NVD description · AI analysis pending
6.1<1%
  • usvn usvn