Show filters
34 Total Results
Displaying 1-10 of 34
Sort by:
Attacker Value
Unknown

CVE-2024-9924

Disclosure Date: October 14, 2024 (last updated January 06, 2025)
The fix for CVE-2024-26261 was incomplete, and and the specific package for OAKlouds from Hgiga remains at risk. Unauthenticated remote attackers still can download arbitrary system files, which may be deleted subsequently .
0
Attacker Value
Unknown

CVE-2024-4299

Disclosure Date: April 29, 2024 (last updated January 05, 2025)
The system configuration interface of HGiga iSherlock (including MailSherlock, SpamSherock, AuditSherlock) fails to filter special characters in certain function parameters, allowing remote attackers with administrative privileges to exploit this vulnerability for Command Injection attacks, enabling execution of arbitrary system commands.
0
Attacker Value
Unknown

CVE-2024-4298

Disclosure Date: April 29, 2024 (last updated April 29, 2024)
The email search interface of HGiga iSherlock (including MailSherlock, SpamSherock, AuditSherlock) fails to filter special characters in certain function parameters, allowing remote attackers with administrative privileges to exploit this vulnerability for Command Injection attacks, enabling execution of arbitrary system commands.
0
Attacker Value
Unknown

CVE-2024-4297

Disclosure Date: April 29, 2024 (last updated January 05, 2025)
The system configuration interface of HGiga iSherlock (including MailSherlock, SpamSherlock, AuditSherlock) fails to filter special characters in certain function parameters, allowing remote attackers with administrative privileges to exploit this vulnerability to download arbitrary system files.
0
Attacker Value
Unknown

CVE-2024-4296

Disclosure Date: April 29, 2024 (last updated January 05, 2025)
The account management interface of HGiga iSherlock (including MailSherlock, SpamSherlock, AuditSherlock) fails to filter special characters in certain function parameters, allowing remote attackers with administrative privileges to exploit this vulnerability to download arbitrary system files.
0
Attacker Value
Unknown

CVE-2024-26261

Disclosure Date: February 15, 2024 (last updated January 24, 2025)
The functionality for file download in HGiga OAKlouds' certain modules contains an Arbitrary File Read and Delete vulnerability. Attackers can put file path in specific request parameters, allowing them to download the file without login. Furthermore, the file will be deleted after being downloaded.
0
Attacker Value
Unknown

CVE-2024-26260

Disclosure Date: February 15, 2024 (last updated January 24, 2025)
The functionality for synchronization in HGiga OAKlouds' certain moudules has an OS Command Injection vulnerability, allowing remote attackers to inject system commands within specific request parameters. This enables the execution of arbitrary code on the remote server without permission.
0
Attacker Value
Unknown

CVE-2023-37292

Disclosure Date: July 21, 2023 (last updated October 08, 2023)
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in HGiga iSherlock 4.5 (iSherlock-user modules), HGiga iSherlock 5.5 (iSherlock-user modules) allows OS Command Injection.This issue affects iSherlock 4.5: before iSherlock-user-4.5-174; iSherlock 5.5: before iSherlock-user-5.5-174.
Attacker Value
Unknown

CVE-2023-25909

Disclosure Date: March 02, 2023 (last updated October 08, 2023)
HGiga OAKlouds file uploading function does not restrict upload of file with dangerous type. An unauthenticated remote attacker can exploit this vulnerability to upload and run arbitrary executable files to perform arbitrary command or disrupt service.
Attacker Value
Unknown

CVE-2023-24841

Disclosure Date: February 24, 2023 (last updated October 08, 2023)
HGiga MailSherlock query function for connection log has a vulnerability of insufficient filtering for user input. An authenticated remote attacker with administrator privilege can exploit this vulnerability to inject and execute arbitrary system commands to perform arbitrary system operation or disrupt service.