Metrics
Affected Vendors & Products
Tue, 22 Oct 2024 18:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
CPEs | cpe:2.3:a:esafenet:cdg:5:*:*:*:*:*:*:* |
Mon, 21 Oct 2024 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Esafenet
Esafenet cdg |
|
CPEs | cpe:2.3:a:esafenet:cdg:*:*:*:*:*:*:*:* | |
Vendors & Products |
Esafenet
Esafenet cdg |
|
Metrics |
ssvc
|
Sat, 19 Oct 2024 10:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability was found in ESAFENET CDG 5 and classified as critical. Affected by this issue is the function connectLogout of the file /com/esafenet/servlet/ajax/MultiServerAjax.java. The manipulation of the argument servername leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | |
Title | ESAFENET CDG MultiServerAjax.java connectLogout sql injection | |
Weaknesses | CWE-89 | |
References |
| |
Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2024-10-19T10:00:08.469Z
Updated: 2024-10-21T14:22:32.797Z
Reserved: 2024-10-18T15:53:40.121Z
Link: CVE-2024-10134
Updated: 2024-10-21T14:20:23.030Z
Status : Analyzed
Published: 2024-10-19T10:15:02.663
Modified: 2024-10-22T18:10:46.467
Link: CVE-2024-10134
No data.