Show filters
34 Total Results
Displaying 21-30 of 34
Sort by:
Attacker Value
Unknown

CVE-2021-22851

Disclosure Date: January 19, 2021 (last updated February 22, 2025)
HGiga EIP product contains SQL Injection vulnerability. Attackers can inject SQL commands into specific URL parameter (document management page) to obtain database schema and data.
Attacker Value
Unknown

CVE-2021-22850

Disclosure Date: January 19, 2021 (last updated February 22, 2025)
HGiga EIP product lacks ineffective access control in certain pages that allow attackers to access database or perform privileged functions.
Attacker Value
Unknown

CVE-2020-35742

Disclosure Date: December 31, 2020 (last updated February 22, 2025)
HGiga MailSherlock contains a vulnerability of SQL Injection. Attackers can inject and launch SQL commands in a URL parameter.
Attacker Value
Unknown

CVE-2020-25848

Disclosure Date: December 31, 2020 (last updated February 22, 2025)
HGiga MailSherlock contains weak authentication flaw that attackers grant privilege remotely with default password generation mechanism.
Attacker Value
Unknown

CVE-2020-25850

Disclosure Date: December 31, 2020 (last updated November 28, 2024)
The function, view the source code, of HGiga MailSherlock does not validate specific characters. Remote attackers can use this flaw to download arbitrary system files.
Attacker Value
Unknown

CVE-2020-35740

Disclosure Date: December 31, 2020 (last updated February 22, 2025)
HGiga MailSherlock does not validate specific URL parameters properly that allows attackers to inject JavaScript syntax for XSS attacks.
Attacker Value
Unknown

CVE-2020-35743

Disclosure Date: December 31, 2020 (last updated February 22, 2025)
HGiga MailSherlock contains a SQL injection flaw. Attackers can inject and launch SQL commands in a URL parameter of specific cgi pages.
Attacker Value
Unknown

CVE-2020-35741

Disclosure Date: December 31, 2020 (last updated February 22, 2025)
HGiga MailSherlock does not validate user parameters on multiple login pages. Attackers can use the vulnerability to inject JavaScript syntax for XSS attacks.
Attacker Value
Unknown

CVE-2020-35851

Disclosure Date: December 31, 2020 (last updated February 22, 2025)
HGiga MailSherlock does not validate specific parameters properly. Attackers can use the vulnerability to launch Command inject attacks remotely and execute arbitrary commands of the system.
Attacker Value
Unknown

CVE-2020-10512

Disclosure Date: April 15, 2020 (last updated February 21, 2025)
HGiga C&Cmail CCMAILQ before olln-calendar-6.0-100.i386.rpm and CCMAILN before olln-calendar-5.0-100.i386.rpm contains a SQL Injection vulnerability which allows attackers to injecting SQL commands in the URL parameter to execute unauthorized commands.