Vulnerabilities > Deltaww
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2021-12-22 | CVE-2021-23228 | Cross-site Scripting vulnerability in Deltaww Diaenergie 1.7.5 DIAEnergie Version 1.7.5 and prior is vulnerable to a reflected cross-site scripting attack through error pages that are returned by “.NET Request.QueryString”. | 4.3 |
2021-12-22 | CVE-2021-31558 | Cross-site Scripting vulnerability in Deltaww Diaenergie 1.7.5 DIAEnergie Version 1.7.5 and prior is vulnerable to stored cross-site scripting when an unauthenticated user injects arbitrary code into the parameter “descr” of the script “DIAE_hierarchyHandler.ashx”. | 4.3 |
2021-12-22 | CVE-2021-44471 | Cross-site Scripting vulnerability in Deltaww Diaenergie 1.7.5 DIAEnergie Version 1.7.5 and prior is vulnerable to stored cross-site scripting when an unauthenticated user injects arbitrary code into the parameter “name” of the script “DIAE_HandlerAlarmGroup.ashx”. | 4.3 |
2021-12-22 | CVE-2021-44544 | Cross-site Scripting vulnerability in Deltaww Diaenergie 1.7.5 DIAEnergie Version 1.7.5 and prior is vulnerable to multiple cross-site scripting vulnerabilities when arbitrary code is injected into the parameter “name” of the script “HandlerEnergyType.ashx”. | 4.3 |
2021-12-09 | CVE-2021-43982 | Stack-based Buffer Overflow vulnerability in Deltaww Cncsoft 1.00.83 Delta Electronics CNCSoft Versions 1.01.30 and prior are vulnerable to a stack-based buffer overflow, which may allow an attacker to execute arbitrary code. | 6.8 |
2021-11-03 | CVE-2021-38403 | Cross-site Scripting vulnerability in Deltaww Dialink 1.2.4.0 Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to cross-site scripting because an authenticated attacker can inject arbitrary JavaScript code into the parameter supplier of the API maintenance, which may allow an attacker to remotely execute code. | 3.5 |
2021-11-03 | CVE-2021-38407 | Cross-site Scripting vulnerability in Deltaww Dialink 1.2.4.0 Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to cross-site scripting because an authenticated attacker can inject arbitrary JavaScript code into the parameter name of the API devices, which may allow an attacker to remotely execute code. | 3.5 |
2021-11-03 | CVE-2021-38411 | Cross-site Scripting vulnerability in Deltaww Dialink 1.2.4.0 Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to cross-site scripting because an authenticated attacker can inject arbitrary JavaScript code into the parameter deviceName of the API modbusWriter-Reader, which may allow an attacker to remotely execute code. | 3.5 |
2021-11-03 | CVE-2021-38416 | Uncontrolled Search Path Element vulnerability in Deltaww Dialink 1.2.4.0 Delta Electronics DIALink versions 1.2.4.0 and prior insecurely loads libraries, which may allow an attacker to use DLL hijacking and takeover the system where the software is installed. | 4.4 |
2021-11-03 | CVE-2021-38418 | Cleartext Transmission of Sensitive Information vulnerability in Deltaww Dialink 1.2.4.0 Delta Electronics DIALink versions 1.2.4.0 and prior runs by default on HTTP, which may allow an attacker to be positioned between the traffic and perform a machine-in-the-middle attack to access information without authorization. | 4.3 |