Show filters
97 Total Results
Displaying 21-30 of 97
Sort by:
Attacker Value
Unknown
CVE-2021-37913
Disclosure Date: September 15, 2021 (last updated February 23, 2025)
The HGiga OAKlouds mobile portal does not filter special characters of the IPv6 Gateway parameter of the network interface card setting page. Remote attackers can use this vulnerability to perform command injection and execute arbitrary commands in the system without logging in.
0
Attacker Value
Unknown
CVE-2021-37912
Disclosure Date: September 15, 2021 (last updated February 23, 2025)
The HGiga OAKlouds mobile portal does not filter special characters of the Ethernet number parameter of the network interface card setting page. Remote attackers can use this vulnerability to perform command injection and execute arbitrary commands in the system without logging in.
0
Attacker Value
Unknown
CVE-2021-24510
Disclosure Date: September 13, 2021 (last updated November 08, 2023)
The MF Gig Calendar WordPress plugin before 1.2 does not sanitise and escape the id GET parameter before outputting back in the admin dashboard when editing an Event, leading to a reflected Cross-Site Scripting issue
0
Attacker Value
Unknown
CVE-2021-22848
Disclosure Date: March 18, 2021 (last updated February 22, 2025)
HGiga MailSherlock contains a SQL Injection. Remote attackers can inject SQL syntax and execute SQL commands in a URL parameter of email pages without privilege.
0
Attacker Value
Unknown
CVE-2021-25309
Disclosure Date: March 02, 2021 (last updated February 22, 2025)
The telnet administrator service running on port 650 on Gigaset DX600A v41.00-175 devices does not implement any lockout or throttling functionality. This situation (together with the weak password policy that forces a 4-digit password) allows remote attackers to easily obtain administrative access via brute-force attacks.
0
Attacker Value
Unknown
CVE-2021-25306
Disclosure Date: March 02, 2021 (last updated February 22, 2025)
A buffer overflow vulnerability in the AT command interface of Gigaset DX600A v41.00-175 devices allows remote attackers to force a device reboot by sending relatively long AT commands.
0
Attacker Value
Unknown
CVE-2021-22852
Disclosure Date: January 19, 2021 (last updated February 22, 2025)
HGiga EIP product contains SQL Injection vulnerability. Attackers can inject SQL commands into specific URL parameter (online registration) to obtain database schema and data.
0
Attacker Value
Unknown
CVE-2021-22851
Disclosure Date: January 19, 2021 (last updated February 22, 2025)
HGiga EIP product contains SQL Injection vulnerability. Attackers can inject SQL commands into specific URL parameter (document management page) to obtain database schema and data.
0
Attacker Value
Unknown
CVE-2021-22850
Disclosure Date: January 19, 2021 (last updated February 22, 2025)
HGiga EIP product lacks ineffective access control in certain pages that allow attackers to access database or perform privileged functions.
0
Attacker Value
Unknown
CVE-2020-23249
Disclosure Date: January 05, 2021 (last updated February 22, 2025)
GigaVUE-OS (GVOS) 5.4 - 5.9 stores a Redis database password in plaintext.
0