CVE-2022-2969 – ICSA-22-307-03 Delta Industrial Automation DIALink Path traversal
https://notcve.org/view.php?id=CVE-2022-2969
Delta Industrial Automation DIALink versions prior to v1.5.0.0 Beta 4 uses an external input to construct a pathname intended to identify a file or directory located underneath a restricted parent directory. However, the software does not properly neutralize special elements within the pathname, which can cause the pathname to resolve to a location outside of the restricted directory. Las versiones DIALink de Delta Industrial Automation anteriores a v1.5.0.0 Beta 4 utilizan una entrada externa para construir un nombre de ruta destinado a identificar un archivo o directorio ubicado debajo de un directorio principal restringido. Sin embargo, el software no neutraliza adecuadamente los elementos especiales dentro del nombre de la ruta, lo que puede hacer que el nombre de la ruta se resuelva en una ubicación fuera del directorio restringido. This vulnerability allows remote attackers to create arbitrary files on affected installations of Delta Industrial Automation DIALink. • https://www.cisa.gov/uscert/ics/advisories/icsa-22-307-03 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •
CVE-2022-43506 – Delta Electronics DIAEnergie SQL Injection
https://notcve.org/view.php?id=CVE-2022-43506
SQL Injection in HandlerTag_KID.ashx in Delta Electronics DIAEnergie versions prior to v1.9.02.001 allows an attacker to inject SQL queries via Network La inyección SQL en HandlerTag_KID.ashx en versiones de Delta Electronics DIAEnergie anteriores a v1.9.02.001 permite a un atacante inyectar consultas SQL a través de la red • https://www.cisa.gov/uscert/ics/advisories/icsa-22-298-06 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2022-41775 – Delta Electronics DIAEnergie SQL Injection
https://notcve.org/view.php?id=CVE-2022-41775
SQL Injection in Handler_CFG.ashx in Delta Electronics DIAEnergie versions prior to v1.9.02.001 allows an attacker to inject SQL queries via Network La inyección SQL en Handler_CFG.ashx en versiones de Delta Electronics DIAEnergie anteriores a la v1.9.02.001 permite a un atacante inyectar consultas SQL a través de la red • https://www.cisa.gov/uscert/ics/advisories/icsa-22-298-06 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2022-43452 – Delta Electronics DIAEnergie SQL Injection
https://notcve.org/view.php?id=CVE-2022-43452
SQL Injection in FtyInfoSetting.aspx in Delta Electronics DIAEnergie versions prior to v1.9.02.001 allows an attacker to inject SQL queries via Network La inyección SQL en FtyInfoSetting.aspx en las versiones de Delta Electronics DIAEnergie anteriores a v1.9.02.001 permite a un atacante inyectar consultas SQL a través de la red • https://www.cisa.gov/uscert/ics/advisories/icsa-22-298-06 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2022-43457 – Delta Electronics DIAEnergie SQL Injection
https://notcve.org/view.php?id=CVE-2022-43457
SQL Injection in HandlerPage_KID.ashx in Delta Electronics DIAEnergie versions prior to v1.9.02.001 allows an attacker to inject SQL queries via Network La inyección SQL en HandlerPage_KID.ashx en versiones de Delta Electronics DIAEnergie anteriores a la v1.9.02.001 permite a un atacante inyectar consultas SQL a través de la red • https://www.cisa.gov/uscert/ics/advisories/icsa-22-298-06 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •