Show filters
78 Total Results
Displaying 11-20 of 78
Sort by:
Attacker Value
Unknown

CVE-2024-28045

Disclosure Date: March 21, 2024 (last updated January 05, 2025)
Improper neutralization of input within the affected product could lead to cross-site scripting.
0
Attacker Value
Unknown

CVE-2024-28040

Disclosure Date: March 21, 2024 (last updated January 05, 2025)
SQL injection vulnerability exists in GetDIAE_astListParameters.
0
Attacker Value
Unknown

CVE-2024-25567

Disclosure Date: March 21, 2024 (last updated January 05, 2025)
Path traversal attack is possible and write outside of the intended directory and may access sensitive information. If a file name is specified that already exists on the file system, then the original file will be overwritten.
0
Attacker Value
Unknown

CVE-2024-23975

Disclosure Date: March 21, 2024 (last updated January 05, 2025)
SQL injection vulnerability exists in GetDIAE_slogListParameters.
0
Attacker Value
Unknown

CVE-2024-23494

Disclosure Date: March 21, 2024 (last updated January 05, 2025)
SQL injection vulnerability exists in GetDIAE_unListParameters.
0
Attacker Value
Unknown

CVE-2024-28891

Disclosure Date: March 21, 2024 (last updated January 05, 2025)
SQL injection vulnerability exists in the script Handler_CFG.ashx.
0
Attacker Value
Unknown

CVE-2024-28029

Disclosure Date: March 21, 2024 (last updated October 18, 2024)
Privileges are not fully verified server-side, which can be abused by a user with limited privileges to bypass authorization and access privileged functionality.
Attacker Value
Unknown

CVE-2024-25937

Disclosure Date: March 21, 2024 (last updated January 25, 2025)
SQL injection vulnerability exists in the script DIAE_tagHandler.ashx.
Attacker Value
Unknown

CVE-2023-0822

Disclosure Date: February 17, 2023 (last updated November 08, 2023)
The affected product DIAEnergie (versions prior to v1.9.03.001) contains improper authorization, which could allow an unauthorized user to bypass authorization and access privileged functionality.
Attacker Value
Unknown

CVE-2022-43452

Disclosure Date: November 17, 2022 (last updated October 27, 2023)
SQL Injection in FtyInfoSetting.aspx in Delta Electronics DIAEnergie versions prior to v1.9.02.001 allows an attacker to inject SQL queries via Network