Show filters
97 Total Results
Displaying 1-10 of 97
Sort by:
Attacker Value
Unknown

CVE-2024-9924

Disclosure Date: October 14, 2024 (last updated January 06, 2025)
The fix for CVE-2024-26261 was incomplete, and and the specific package for OAKlouds from Hgiga remains at risk. Unauthenticated remote attackers still can download arbitrary system files, which may be deleted subsequently .
0
Attacker Value
Unknown

CVE-2024-8105

Disclosure Date: August 26, 2024 (last updated August 27, 2024)
A vulnerability related to the use an insecure Platform Key (PK) has been discovered. An attacker with the compromised PK private key can create malicious UEFI software that is signed with a trusted key that has been compromised.
0
Attacker Value
Unknown

CVE-2024-4299

Disclosure Date: April 29, 2024 (last updated January 05, 2025)
The system configuration interface of HGiga iSherlock (including MailSherlock, SpamSherock, AuditSherlock) fails to filter special characters in certain function parameters, allowing remote attackers with administrative privileges to exploit this vulnerability for Command Injection attacks, enabling execution of arbitrary system commands.
0
Attacker Value
Unknown

CVE-2024-4298

Disclosure Date: April 29, 2024 (last updated April 29, 2024)
The email search interface of HGiga iSherlock (including MailSherlock, SpamSherock, AuditSherlock) fails to filter special characters in certain function parameters, allowing remote attackers with administrative privileges to exploit this vulnerability for Command Injection attacks, enabling execution of arbitrary system commands.
0
Attacker Value
Unknown

CVE-2024-4297

Disclosure Date: April 29, 2024 (last updated January 05, 2025)
The system configuration interface of HGiga iSherlock (including MailSherlock, SpamSherlock, AuditSherlock) fails to filter special characters in certain function parameters, allowing remote attackers with administrative privileges to exploit this vulnerability to download arbitrary system files.
0
Attacker Value
Unknown

CVE-2024-4296

Disclosure Date: April 29, 2024 (last updated January 05, 2025)
The account management interface of HGiga iSherlock (including MailSherlock, SpamSherlock, AuditSherlock) fails to filter special characters in certain function parameters, allowing remote attackers with administrative privileges to exploit this vulnerability to download arbitrary system files.
0
Attacker Value
Unknown

CVE-2024-26261

Disclosure Date: February 15, 2024 (last updated January 24, 2025)
The functionality for file download in HGiga OAKlouds' certain modules contains an Arbitrary File Read and Delete vulnerability. Attackers can put file path in specific request parameters, allowing them to download the file without login. Furthermore, the file will be deleted after being downloaded.
0
Attacker Value
Unknown

CVE-2024-26260

Disclosure Date: February 15, 2024 (last updated January 24, 2025)
The functionality for synchronization in HGiga OAKlouds' certain moudules has an OS Command Injection vulnerability, allowing remote attackers to inject system commands within specific request parameters. This enables the execution of arbitrary code on the remote server without permission.
0
Attacker Value
Unknown

CVE-2023-50842

Disclosure Date: December 28, 2023 (last updated January 05, 2024)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Matthew Fries MF Gig Calendar.This issue affects MF Gig Calendar: from n/a through 1.2.1.
Attacker Value
Unknown

CVE-2023-37970

Disclosure Date: July 27, 2023 (last updated October 08, 2023)
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Matthew Fries MF Gig Calendar plugin <= 1.2 versions.