ZeroHour

Vulnerabilities

3 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-39851
webchess v1.0 was discovered to contain a SQL injection vulnerability via the $playerID parameter at mainmenu.php.

webchess v1.0 was discovered to contain a SQL injection vulnerability via the $playerID parameter at mainmenu.php. NOTE: this is disputed by a third party who indicates that the playerID is a session variable controlled by the server, and thus cannot be used for exploitation.

NVD description · AI analysis pending
9.8<1% PoC
  • webchess project webchess
CVE-2023-22959
WebChess through 0.9.0 and 1.0.0.rc2 allows SQL injection:

WebChess through 0.9.0 and 1.0.0.rc2 allows SQL injection: mainmenu.php, chess.php, and opponentspassword.php (txtFirstName, txtLastName).

NVD description · AI analysis pending
8.814% PoC
  • webchess project webchess
CVE-2019-20896
WebChess 1.0 allows SQL injection via the messageFrom, gameID, opponent, messageID, or to parameter.

WebChess 1.0 allows SQL injection via the messageFrom, gameID, opponent, messageID, or to parameter.

NVD description · AI analysis pending
9.8<1%
  • webchess project webchess