CVE-2012-1415
- EPSS 1.06%
- Veröffentlicht 28.12.2014 02:59:03
- Zuletzt bearbeitet 06.05.2026 22:30:45
Cross-site request forgery (CSRF) vulnerability in lib/logout.php in DFLabs PTK 1.0.5 and earlier allows remote attackers to hijack the authentication of administrators or investigators for requests that trigger a logout.
- EPSS 1.37%
- Veröffentlicht 17.11.2012 21:55:04
- Zuletzt bearbeitet 16.06.2026 23:47:33
DFLabs PTK 1.0.5 stores data files with predictable names under the web document root with insufficient access control, which allows remote attackers to read logs, images, or reports via a direct request to the file in the (1) log, (2) images, or (3)...
CVE-2012-5902
- EPSS 1.16%
- Veröffentlicht 17.11.2012 21:55:04
- Zuletzt bearbeitet 16.06.2026 23:47:33
Cross-site scripting (XSS) vulnerability in ptk/lib/modal_bookmark.php in DFLabs PTK 1.0.5 allows remote attackers to inject arbitrary web script or HTML via the arg4 parameter.
CVE-2008-6793
- EPSS 6.93%
- Veröffentlicht 07.05.2009 17:30:03
- Zuletzt bearbeitet 16.06.2026 23:02:59
The get_file_type function in lib/file_content.php in DFLabs PTK 0.1, 0.2, and 1.0 allows remote attackers to execute arbitrary commands via shell metacharacters after an arg1= sequence in a filename within a forensic image.
CVE-2009-0917
- EPSS 1.54%
- Veröffentlicht 16.03.2009 19:30:00
- Zuletzt bearbeitet 16.06.2026 23:06:06
Cross-site scripting (XSS) vulnerability in DFLabs PTK 1.0.0 through 1.0.4 allows remote attackers to inject arbitrary web script or HTML by providing a forensic image containing HTML documents, which are rendered in web browsers during inspection by...
CVE-2009-0918
- EPSS 2.73%
- Veröffentlicht 16.03.2009 19:30:00
- Zuletzt bearbeitet 16.06.2026 23:06:06
Multiple unspecified vulnerabilities in DFLabs PTK 1.0.0 through 1.0.4 allow remote attackers to execute arbitrary commands in processes launched by PTK's Apache HTTP Server via (1) "external tools" or (2) a crafted forensic image.