Metrics
Affected Vendors & Products
Fri, 01 Nov 2024 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Esafenet
Esafenet cdg |
|
CPEs | cpe:2.3:a:esafenet:cdg:5:*:*:*:*:*:*:* | |
Vendors & Products |
Esafenet
Esafenet cdg |
|
Metrics |
ssvc
|
Fri, 01 Nov 2024 02:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability was found in ESAFENET CDG 5. It has been classified as critical. Affected is the function removeHookInvalidCourse of the file /com/esafenet/servlet/system/HookInvalidCourseService.java. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | |
Title | ESAFENET CDG HookInvalidCourseService.java removeHookInvalidCourse sql injection | |
Weaknesses | CWE-89 | |
References |
| |
Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2024-11-01T02:00:10.894Z
Updated: 2024-11-01T13:54:59.965Z
Reserved: 2024-10-31T15:46:54.853Z
Link: CVE-2024-10612
Updated: 2024-11-01T13:54:35.955Z
Status : Analyzed
Published: 2024-11-01T03:15:02.617
Modified: 2024-11-05T16:20:43.557
Link: CVE-2024-10612
No data.