Show filters
43 Total Results
Displaying 41-43 of 43
Sort by:
Attacker Value
Unknown
CVE-2024-9536
Disclosure Date: October 05, 2024 (last updated October 06, 2024)
A vulnerability was found in ESAFENET CDG V5. It has been rated as critical. Affected by this issue is some unknown functionality of the file /MultiServerBackService?path=1. The manipulation of the argument fileId leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
0
Attacker Value
Unknown
CVE-2017-18636
Disclosure Date: September 30, 2019 (last updated November 27, 2024)
CDG through 2017-01-01 allows downloadDocument.jsp?command=download&pathAndName= directory traversal.
0
Attacker Value
Unknown
CVE-2019-9632
Disclosure Date: March 08, 2019 (last updated November 27, 2024)
ESAFENET CDG V3 and V5 has an arbitrary file download vulnerability via the fileName parameter in download.jsp because the InstallationPack parameter is mishandled in a /CDGServer3/ClientAjax request.
0