14 results (0.013 seconds)

CVSS: 8.8EPSS: 0%CPEs: 2EXPL: 1

A vulnerability was found in D-Link DAR-7000 up to 20230922. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /log/decodmail.php. The manipulation of the argument file leads to deserialization. The attack may be launched remotely. • https://github.com/flyyue2001/cve/blob/main/D-LINK%20-DAR-7000_rce_%20decodmail.md https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10354 https://vuldb.com/?ctiid.270368 https://vuldb.com/?id.270368 https://vuldb.com/?submit.368099 • CWE-502: Deserialization of Untrusted Data •

CVSS: 9.8EPSS: 0%CPEs: 2EXPL: 1

A vulnerability has been found in D-Link DAR-7000 up to 20231126 and classified as critical. This vulnerability affects unknown code of the file /user/inc/workidajax.php. The manipulation of the argument id leads to sql injection. The exploit has been disclosed to the public and may be used. VDB-247162 is the identifier assigned to this vulnerability. • https://github.com/flyyue2001/cve/blob/main/D-LINK%20-DAR-7000_sql_workidajax.md https://vuldb.com/?ctiid.247162 https://vuldb.com/?id.247162 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVSS: 9.8EPSS: 0%CPEs: 2EXPL: 1

D-Link Online behavior audit gateway DAR-7000 V31R02B1413C is vulnerable to SQL Injection via /importexport.php. La puerta de enlace de auditoría de comportamiento de D-Link Online DAR-7000 V31R02B1413C es vulnerable a la inyección SQL a través de /importexport.php. • https://github.com/llixixi/cve/blob/main/D-LINK-DAR-7000_sql_%20importexport.md • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVSS: 9.8EPSS: 0%CPEs: 2EXPL: 1

D-Link Online behavior audit gateway DAR-7000 V31R02B1413C is vulnerable to SQL Injection via /log/mailrecvview.php. La puerta de enlace de auditoría de comportamiento de D-Link Online DAR-7000 V31R02B1413C es vulnerable a la inyección SQL a través de /log/mailrecvview.php. • https://github.com/llixixi/cve/blob/main/D-LINK-DAR-7000_rce_%20mailrecvview.md • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVSS: 8.8EPSS: 0%CPEs: 2EXPL: 1

A vulnerability was found in D-Link DAR-7000 up to 20151231. It has been rated as critical. Affected by this issue is some unknown functionality of the file /sysmanage/edit_manageadmin.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. • https://github.com/flyyue2001/cve/blob/main/D-LINK%20-DAR-7000%E5%AD%98%E5%9C%A8sql%E6%B3%A8%E5%85%A5:sysmanage:edit_manageadmin.php.md https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10354 https://vuldb.com/?ctiid.240992 https://vuldb.com/?id.240992 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •