CVE-2022-24688
- EPSS 3.92%
- Veröffentlicht 18.07.2022 13:15:09
- Zuletzt bearbeitet 21.11.2024 06:50:52
An issue was discovered in DSK DSKNet 2.16.136.0 and 2.17.136.5. The Touch settings allow unrestricted file upload (and consequently Remote Code Execution) via PDF upload with PHP content and a .php extension. The attacker must hijack or obtain privi...
CVE-2022-24689
- EPSS 0.19%
- Veröffentlicht 18.07.2022 13:15:09
- Zuletzt bearbeitet 21.11.2024 06:50:53
An issue was discovered in DSK DSKNet 2.16.136.0 and 2.17.136.5. It mishandles access control. This allows a remote attacker to access account information pages (including personal data) without being authenticated. The collected information includes...
CVE-2022-24690
- EPSS 2.16%
- Veröffentlicht 18.07.2022 13:15:09
- Zuletzt bearbeitet 21.11.2024 06:50:53
An issue was discovered in DSK DSKNet 2.16.136.0 and 2.17.136.5. A PresAbs.php SQL Injection vulnerability allows unauthenticated users to taint database data and extract sensitive information via crafted HTTP requests. The type of SQL Injection is b...
CVE-2022-24691
- EPSS 1.08%
- Veröffentlicht 18.07.2022 13:15:09
- Zuletzt bearbeitet 21.11.2024 06:50:53
An issue was discovered in DSK DSKNet 2.16.136.0 and 2.17.136.5. A SQL Injection vulnerability allows authenticated users to taint database data and extract sensitive information via crafted HTTP requests. The type of SQL Injection is blind boolean b...
CVE-2022-24692
- EPSS 0.38%
- Veröffentlicht 18.07.2022 13:15:09
- Zuletzt bearbeitet 21.11.2024 06:50:53
An issue was discovered in DSK DSKNet 2.16.136.0 and 2.17.136.5. The new menu option within the general Parameters page is vulnerable to stored XSS. The attacker can create a menu option, make it visible to every application user, and conduct session...