Show filters
17 Total Results
Displaying 11-17 of 17
Sort by:
Attacker Value
Unknown
CVE-2021-37912
Disclosure Date: September 15, 2021 (last updated February 23, 2025)
The HGiga OAKlouds mobile portal does not filter special characters of the Ethernet number parameter of the network interface card setting page. Remote attackers can use this vulnerability to perform command injection and execute arbitrary commands in the system without logging in.
0
Attacker Value
Unknown
CVE-2021-22852
Disclosure Date: January 19, 2021 (last updated February 22, 2025)
HGiga EIP product contains SQL Injection vulnerability. Attackers can inject SQL commands into specific URL parameter (online registration) to obtain database schema and data.
0
Attacker Value
Unknown
CVE-2021-22851
Disclosure Date: January 19, 2021 (last updated February 22, 2025)
HGiga EIP product contains SQL Injection vulnerability. Attackers can inject SQL commands into specific URL parameter (document management page) to obtain database schema and data.
0
Attacker Value
Unknown
CVE-2021-22850
Disclosure Date: January 19, 2021 (last updated February 22, 2025)
HGiga EIP product lacks ineffective access control in certain pages that allow attackers to access database or perform privileged functions.
0
Attacker Value
Unknown
CVE-2020-10512
Disclosure Date: April 15, 2020 (last updated February 21, 2025)
HGiga C&Cmail CCMAILQ before olln-calendar-6.0-100.i386.rpm and CCMAILN before olln-calendar-5.0-100.i386.rpm contains a SQL Injection vulnerability which allows attackers to injecting SQL commands in the URL parameter to execute unauthorized commands.
0
Attacker Value
Unknown
CVE-2020-10511
Disclosure Date: April 15, 2020 (last updated February 21, 2025)
HGiga C&Cmail CCMAILQ before olln-base-6.0-418.i386.rpm and CCMAILN before olln-base-5.0-418.i386.rpm contains insecure configurations. Attackers can exploit these flaws to access unauthorized functionality via a crafted URL.
0
Attacker Value
Unknown
SQL Injection exists in MailSherlock before 1.5.235 for OAKlouds
Disclosure Date: February 11, 2019 (last updated November 27, 2024)
SQL Injection exists in MailSherlock before 1.5.235 for OAKlouds allows an unauthenticated user to extract the subjects of the emails of other users within the enterprise via the select_mid parameter in an letgo.cgi request.
0