The web server of the E1 Zoom camera through 3.0.0.716 discloses its configuration via the /conf/ directory that is mapped to a publicly accessible path. In this way an attacker can download the entir ...
Continue ReadingJuly 17, 2022
The export function in SoftGuard Web (SGW) before 5.1.5 allows directory traversal to read an arbitrary local file via export or man.tcl.Read More ...
Continue ReadingJuly 17, 2022
SoftGuard Web (SGW) before 5.1.5 allows HTML injection.Read More ...
Continue ReadingJuly 17, 2022
An issue was discovered in Gentics CMS before 5.43.1. There is stored XSS in the profile description and in the username.Read More ...
Continue ReadingJuly 17, 2022
An issue was discovered in Infiray IRAY-A8Z3 1.0.957. The webserver contains an endpoint that can execute arbitrary commands by manipulating the cmd_string URL parameter.Read More ...
Continue ReadingJuly 17, 2022
An issue was discovered in Open Design Alliance Drawings SDK before 2023.3. An Out-of-Bounds Read vulnerability exists when reading DWG files in a recovery mode. An attacker can leverage this vulnerab ...
Continue ReadingJuly 17, 2022
An issue was discovered in Open Design Alliance Drawings SDK before 2023.2. An Out-of-Bounds Read vulnerability exists when rendering a .dwg file after it's opened in the recovery mode. An attacker ca ...
Continue ReadingJuly 17, 2022
An issue was discovered in Open Design Alliance Drawings SDK before 2023.3. An Out-of-Bounds Read vulnerability exists when reading a DWG file with an invalid vertex number in a recovery mode. An atta ...
Continue ReadingJuly 17, 2022
Back to Main