Metrics
Affected Vendors & Products
Wed, 30 Oct 2024 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-22 |
Fri, 25 Oct 2024 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Esafenet
Esafenet cdg |
|
CPEs | cpe:2.3:a:esafenet:cdg:5:*:*:*:*:*:*:* | |
Vendors & Products |
Esafenet
Esafenet cdg |
|
Metrics |
ssvc
|
Fri, 25 Oct 2024 12:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability classified as problematic was found in ESAFENET CDG 5. Affected by this vulnerability is the function actionViewDecyptFile of the file /com/esafenet/servlet/client/DecryptApplicationService.java. The manipulation of the argument decryptFileId with the input ../../../Windows/System32/drivers/etc/hosts leads to path traversal: '../filedir'. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The affected function has a typo and is missing an R. The vendor was contacted early about this disclosure but did not respond in any way. | |
Title | ESAFENET CDG DecryptApplicationService.java actionViewDecyptFile path traversal | |
Weaknesses | CWE-24 | |
References |
| |
Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2024-10-25T12:00:16.480Z
Updated: 2024-10-25T18:49:16.011Z
Reserved: 2024-10-25T05:53:44.360Z
Link: CVE-2024-10379
Updated: 2024-10-25T18:49:06.835Z
Status : Analyzed
Published: 2024-10-25T12:15:02.890
Modified: 2024-10-30T18:54:15.323
Link: CVE-2024-10379
No data.