Filtered by vendor Esafenet Subscriptions
Total 4 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2024-46510 1 Esafenet 1 Cdg 2024-10-04 7.6 High
ESAFENET CDG v5 was discovered to contain a SQL injection vulnerability via the id parameter in the NavigationAjax interface
CVE-2019-9632 1 Esafenet 1 Electronic Document Security Management System 2024-09-16 N/A
ESAFENET CDG V3 and V5 has an arbitrary file download vulnerability via the fileName parameter in download.jsp because the InstallationPack parameter is mishandled in a /CDGServer3/ClientAjax request.
CVE-2024-42885 1 Esafenet 1 Cdg 2024-09-05 9.1 Critical
SQL Injection vulnerability in ESAFENET CDG 5.6 and before allows an attacker to execute arbitrary code via the id parameter of the data.jsp page.
CVE-2017-18636 1 Esafenet 1 Cdg 2024-08-05 7.5 High
CDG through 2017-01-01 allows downloadDocument.jsp?command=download&pathAndName= directory traversal.