CVE-2024-6525 – D-Link DAR-7000 decodmail.php deserialization
https://notcve.org/view.php?id=CVE-2024-6525
A vulnerability was found in D-Link DAR-7000 up to 20230922. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /log/decodmail.php. The manipulation of the argument file leads to deserialization. The attack may be launched remotely. • https://github.com/flyyue2001/cve/blob/main/D-LINK%20-DAR-7000_rce_%20decodmail.md https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10354 https://vuldb.com/?ctiid.270368 https://vuldb.com/?id.270368 https://vuldb.com/?submit.368099 • CWE-502: Deserialization of Untrusted Data •
CVE-2023-6581 – D-Link DAR-7000 workidajax.php sql injection
https://notcve.org/view.php?id=CVE-2023-6581
A vulnerability has been found in D-Link DAR-7000 up to 20231126 and classified as critical. This vulnerability affects unknown code of the file /user/inc/workidajax.php. The manipulation of the argument id leads to sql injection. The exploit has been disclosed to the public and may be used. VDB-247162 is the identifier assigned to this vulnerability. • https://github.com/flyyue2001/cve/blob/main/D-LINK%20-DAR-7000_sql_workidajax.md https://vuldb.com/?ctiid.247162 https://vuldb.com/?id.247162 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2023-42406
https://notcve.org/view.php?id=CVE-2023-42406
SQL injection vulnerability in D-Link Online behavior audit gateway DAR-7000 V31R02B1413C allows a remote attacker to obtain sensitive information and execute arbitrary code via the editrole.php component. Vulnerabilidad de inyección SQL en la puerta de enlace de auditoría de comportamiento de D-Link Online DAR-7000 V31R02B1413C permite a un atacante remoto obtener información confidencial y ejecutar código arbitrario a través del componente editrole.php. • https://github.com/1dreamGN/CVE/blob/main/CVE-2023-42406.md https://github.com/flyyue2001/cve/blob/main/D-LINK%20-DAR-7000_sql_:sysmanage:editrole.php.md • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2023-5322 – D-Link DAR-7000 edit_manageadmin.php sql injection
https://notcve.org/view.php?id=CVE-2023-5322
A vulnerability was found in D-Link DAR-7000 up to 20151231. It has been rated as critical. Affected by this issue is some unknown functionality of the file /sysmanage/edit_manageadmin.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. • https://github.com/flyyue2001/cve/blob/main/D-LINK%20-DAR-7000%E5%AD%98%E5%9C%A8sql%E6%B3%A8%E5%85%A5:sysmanage:edit_manageadmin.php.md https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10354 https://vuldb.com/?ctiid.240992 https://vuldb.com/?id.240992 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2023-5153 – D-Link DAR-8000 querysql.php sql injection
https://notcve.org/view.php?id=CVE-2023-5153
A vulnerability, which was classified as critical, was found in D-Link DAR-8000 up to 20151231. This affects an unknown part of the file /Tool/querysql.php. The manipulation leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. • https://github.com/llixixi/cve/blob/main/D-LINK-DAR-8000-10_sql_%20querysql.md https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10354 https://vuldb.com/?ctiid.240249 https://vuldb.com/?id.240249 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •