Vulnerabilities (CVE)

Filtered by vendor Esafenet Subscribe
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-18636 1 Esafenet 1 Cdg 2024-02-28 5.0 MEDIUM 7.5 HIGH
CDG through 2017-01-01 allows downloadDocument.jsp?command=download&pathAndName= directory traversal.
CVE-2019-9632 1 Esafenet 1 Electronic Document Security Management System 2024-02-28 5.0 MEDIUM 7.5 HIGH
ESAFENET CDG V3 and V5 has an arbitrary file download vulnerability via the fileName parameter in download.jsp because the InstallationPack parameter is mishandled in a /CDGServer3/ClientAjax request.