Show filters
78 Total Results
Displaying 11-20 of 78
Sort by:
Attacker Value
Unknown
CVE-2024-28045
Disclosure Date: March 21, 2024 (last updated January 05, 2025)
Improper neutralization of input within the affected product could lead to cross-site scripting.
0
Attacker Value
Unknown
CVE-2024-28040
Disclosure Date: March 21, 2024 (last updated January 05, 2025)
SQL injection vulnerability exists in GetDIAE_astListParameters.
0
Attacker Value
Unknown
CVE-2024-25567
Disclosure Date: March 21, 2024 (last updated January 05, 2025)
Path traversal attack is possible and write outside of the intended directory and may access sensitive information. If a file name is specified that already exists on the file system, then the original file will be overwritten.
0
Attacker Value
Unknown
CVE-2024-23975
Disclosure Date: March 21, 2024 (last updated January 05, 2025)
SQL injection vulnerability exists in GetDIAE_slogListParameters.
0
Attacker Value
Unknown
CVE-2024-23494
Disclosure Date: March 21, 2024 (last updated January 05, 2025)
SQL injection vulnerability exists in GetDIAE_unListParameters.
0
Attacker Value
Unknown
CVE-2024-28891
Disclosure Date: March 21, 2024 (last updated January 05, 2025)
SQL injection vulnerability exists in the script Handler_CFG.ashx.
0
Attacker Value
Unknown
CVE-2024-28029
Disclosure Date: March 21, 2024 (last updated October 18, 2024)
Privileges are not fully verified server-side, which can be abused by a user with limited privileges to bypass authorization and access privileged functionality.
0
Attacker Value
Unknown
CVE-2024-25937
Disclosure Date: March 21, 2024 (last updated January 25, 2025)
SQL injection vulnerability exists in the script DIAE_tagHandler.ashx.
0
Attacker Value
Unknown
CVE-2023-0822
Disclosure Date: February 17, 2023 (last updated November 08, 2023)
The affected product DIAEnergie (versions prior to v1.9.03.001) contains improper authorization, which could allow an unauthorized user to bypass authorization and access privileged functionality.
0
Attacker Value
Unknown
CVE-2022-43452
Disclosure Date: November 17, 2022 (last updated October 27, 2023)
SQL Injection in
FtyInfoSetting.aspx in Delta Electronics DIAEnergie versions prior to v1.9.02.001 allows an attacker to inject SQL queries via Network
0