ZeroHour

Vulnerabilities

4 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2018-12273
+1 in the same advisory: …12272
The /edit URI in the DMS component in Ximdex 4.0 has XSS via the Ciudad or Nombre parameter.

The /edit URI in the DMS component in Ximdex 4.0 has XSS via the Ciudad or Nombre parameter.

NVD description · AI analysis pending
6.1<1% PoC
  • ximdex ximdex
CVE-2018-12047
xfind/search in Ximdex 4.0 has XSS via the filter[n][value] parameters for non-negative values of n, as demonstrated by n equal to 0 through 12.

xfind/search in Ximdex 4.0 has XSS via the filter[n][value] parameters for non-negative values of n, as demonstrated by n equal to 0 through 12.

NVD description · AI analysis pending
6.1<1% PoC
  • ximdex ximdex
CVE-2018-11735
index.php?action=createaccount in Ximdex 4.0 has XSS via the sname or fname parameter.

index.php?action=createaccount in Ximdex 4.0 has XSS via the sname or fname parameter.

NVD description · AI analysis pending
6.1<1%
  • ximdex ximdex