Show filters
97 Total Results
Displaying 21-30 of 97
Sort by:
Attacker Value
Unknown

CVE-2021-37913

Disclosure Date: September 15, 2021 (last updated February 23, 2025)
The HGiga OAKlouds mobile portal does not filter special characters of the IPv6 Gateway parameter of the network interface card setting page. Remote attackers can use this vulnerability to perform command injection and execute arbitrary commands in the system without logging in.
0
Attacker Value
Unknown

CVE-2021-37912

Disclosure Date: September 15, 2021 (last updated February 23, 2025)
The HGiga OAKlouds mobile portal does not filter special characters of the Ethernet number parameter of the network interface card setting page. Remote attackers can use this vulnerability to perform command injection and execute arbitrary commands in the system without logging in.
Attacker Value
Unknown

CVE-2021-24510

Disclosure Date: September 13, 2021 (last updated November 08, 2023)
The MF Gig Calendar WordPress plugin before 1.2 does not sanitise and escape the id GET parameter before outputting back in the admin dashboard when editing an Event, leading to a reflected Cross-Site Scripting issue
Attacker Value
Unknown

CVE-2021-22848

Disclosure Date: March 18, 2021 (last updated February 22, 2025)
HGiga MailSherlock contains a SQL Injection. Remote attackers can inject SQL syntax and execute SQL commands in a URL parameter of email pages without privilege.
Attacker Value
Unknown

CVE-2021-25309

Disclosure Date: March 02, 2021 (last updated February 22, 2025)
The telnet administrator service running on port 650 on Gigaset DX600A v41.00-175 devices does not implement any lockout or throttling functionality. This situation (together with the weak password policy that forces a 4-digit password) allows remote attackers to easily obtain administrative access via brute-force attacks.
Attacker Value
Unknown

CVE-2021-25306

Disclosure Date: March 02, 2021 (last updated February 22, 2025)
A buffer overflow vulnerability in the AT command interface of Gigaset DX600A v41.00-175 devices allows remote attackers to force a device reboot by sending relatively long AT commands.
Attacker Value
Unknown

CVE-2021-22852

Disclosure Date: January 19, 2021 (last updated February 22, 2025)
HGiga EIP product contains SQL Injection vulnerability. Attackers can inject SQL commands into specific URL parameter (online registration) to obtain database schema and data.
Attacker Value
Unknown

CVE-2021-22851

Disclosure Date: January 19, 2021 (last updated February 22, 2025)
HGiga EIP product contains SQL Injection vulnerability. Attackers can inject SQL commands into specific URL parameter (document management page) to obtain database schema and data.
Attacker Value
Unknown

CVE-2021-22850

Disclosure Date: January 19, 2021 (last updated February 22, 2025)
HGiga EIP product lacks ineffective access control in certain pages that allow attackers to access database or perform privileged functions.
Attacker Value
Unknown

CVE-2020-23249

Disclosure Date: January 05, 2021 (last updated February 22, 2025)
GigaVUE-OS (GVOS) 5.4 - 5.9 stores a Redis database password in plaintext.