CVE-2024-6525 – D-Link DAR-7000 decodmail.php deserialization
https://notcve.org/view.php?id=CVE-2024-6525
A vulnerability was found in D-Link DAR-7000 up to 20230922. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /log/decodmail.php. The manipulation of the argument file leads to deserialization. The attack may be launched remotely. • https://github.com/flyyue2001/cve/blob/main/D-LINK%20-DAR-7000_rce_%20decodmail.md https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10354 https://vuldb.com/?ctiid.270368 https://vuldb.com/?id.270368 https://vuldb.com/?submit.368099 • CWE-502: Deserialization of Untrusted Data •
CVE-2023-6581 – D-Link DAR-7000 workidajax.php sql injection
https://notcve.org/view.php?id=CVE-2023-6581
A vulnerability has been found in D-Link DAR-7000 up to 20231126 and classified as critical. This vulnerability affects unknown code of the file /user/inc/workidajax.php. The manipulation of the argument id leads to sql injection. The exploit has been disclosed to the public and may be used. VDB-247162 is the identifier assigned to this vulnerability. • https://github.com/flyyue2001/cve/blob/main/D-LINK%20-DAR-7000_sql_workidajax.md https://vuldb.com/?ctiid.247162 https://vuldb.com/?id.247162 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2023-42406
https://notcve.org/view.php?id=CVE-2023-42406
SQL injection vulnerability in D-Link Online behavior audit gateway DAR-7000 V31R02B1413C allows a remote attacker to obtain sensitive information and execute arbitrary code via the editrole.php component. Vulnerabilidad de inyección SQL en la puerta de enlace de auditoría de comportamiento de D-Link Online DAR-7000 V31R02B1413C permite a un atacante remoto obtener información confidencial y ejecutar código arbitrario a través del componente editrole.php. • https://github.com/1dreamGN/CVE/blob/main/CVE-2023-42406.md https://github.com/flyyue2001/cve/blob/main/D-LINK%20-DAR-7000_sql_:sysmanage:editrole.php.md • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2023-44693
https://notcve.org/view.php?id=CVE-2023-44693
D-Link Online behavior audit gateway DAR-7000 V31R02B1413C is vulnerable to SQL Injection via /importexport.php. La puerta de enlace de auditoría de comportamiento de D-Link Online DAR-7000 V31R02B1413C es vulnerable a la inyección SQL a través de /importexport.php. • https://github.com/llixixi/cve/blob/main/D-LINK-DAR-7000_sql_%20importexport.md • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2023-44694
https://notcve.org/view.php?id=CVE-2023-44694
D-Link Online behavior audit gateway DAR-7000 V31R02B1413C is vulnerable to SQL Injection via /log/mailrecvview.php. La puerta de enlace de auditoría de comportamiento de D-Link Online DAR-7000 V31R02B1413C es vulnerable a la inyección SQL a través de /log/mailrecvview.php. • https://github.com/llixixi/cve/blob/main/D-LINK-DAR-7000_rce_%20mailrecvview.md • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •