CVE-2012-1415
- EPSS 0.33%
- Veröffentlicht 28.12.2014 02:59:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
Cross-site request forgery (CSRF) vulnerability in lib/logout.php in DFLabs PTK 1.0.5 and earlier allows remote attackers to hijack the authentication of administrators or investigators for requests that trigger a logout.
- EPSS 0.33%
- Veröffentlicht 17.11.2012 21:55:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
DFLabs PTK 1.0.5 stores data files with predictable names under the web document root with insufficient access control, which allows remote attackers to read logs, images, or reports via a direct request to the file in the (1) log, (2) images, or (3)...
CVE-2012-5902
- EPSS 0.29%
- Veröffentlicht 17.11.2012 21:55:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
Cross-site scripting (XSS) vulnerability in ptk/lib/modal_bookmark.php in DFLabs PTK 1.0.5 allows remote attackers to inject arbitrary web script or HTML via the arg4 parameter.
CVE-2008-6793
- EPSS 8.84%
- Veröffentlicht 07.05.2009 17:30:03
- Zuletzt bearbeitet 09.04.2025 00:30:58
The get_file_type function in lib/file_content.php in DFLabs PTK 0.1, 0.2, and 1.0 allows remote attackers to execute arbitrary commands via shell metacharacters after an arg1= sequence in a filename within a forensic image.
CVE-2009-0917
- EPSS 2.25%
- Veröffentlicht 16.03.2009 19:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Cross-site scripting (XSS) vulnerability in DFLabs PTK 1.0.0 through 1.0.4 allows remote attackers to inject arbitrary web script or HTML by providing a forensic image containing HTML documents, which are rendered in web browsers during inspection by...
CVE-2009-0918
- EPSS 1.95%
- Veröffentlicht 16.03.2009 19:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple unspecified vulnerabilities in DFLabs PTK 1.0.0 through 1.0.4 allow remote attackers to execute arbitrary commands in processes launched by PTK's Apache HTTP Server via (1) "external tools" or (2) a crafted forensic image.