ZeroHour

Vulnerabilities

8 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2020-23715
Directory Traversal vulnerability in Webport CMS 1.19.10.17121 via the file parameter to file/download.

Directory Traversal vulnerability in Webport CMS 1.19.10.17121 via the file parameter to file/download.

NVD description · AI analysis pending
8.62% PoC
  • webport cms project webport cms
CVE-2020-18668
+2 in the same advisory: …18664 …18665
Cross Site Scripting (XSS) vulnerabililty in WebPort <=1.19.1 via the description parameter to script/listcalls.

Cross Site Scripting (XSS) vulnerabililty in WebPort <=1.19.1 via the description parameter to script/listcalls.

NVD description · AI analysis pending
5.4
group max
<1% PoC
  • webport web port
CVE-2020-18667
SQL Injection vulnerability in WebPort <=1.19.1 via the new connection, parameter name in type-conn.

SQL Injection vulnerability in WebPort <=1.19.1 via the new connection, parameter name in type-conn.

NVD description · AI analysis pending
9.81% PoC
  • webport webport
CVE-2020-23659
WebPort-v1.19.17121 is affected by Cross Site Scripting (XSS) on the "connections" feature.

WebPort-v1.19.17121 is affected by Cross Site Scripting (XSS) on the "connections" feature.

NVD description · AI analysis pending
5.4<1% PoC
  • webport web port
CVE-2019-12461
+1 in the same advisory: …12460
Web Port 1.19.1 allows XSS via the /log type parameter.

Web Port 1.19.1 allows XSS via the /log type parameter.

NVD description · AI analysis pending
6.110% PoC ×2
  • webport web port