cve/2024/CVE-2024-10660.md
2025-09-29 16:08:36 +00:00

28 lines
1.2 KiB
Markdown

### [CVE-2024-10660](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-10660)
![](https://img.shields.io/static/v1?label=Product&message=CDG&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=%3D%205%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=SQL%20Injection&color=brighgreen)
### Description
A vulnerability, which was classified as critical, was found in ESAFENET CDG 5. This affects the function deleteHook of the file /com/esafenet/servlet/policy/HookService.java. The manipulation of the argument hookId leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
### POC
#### Reference
No PoCs from references.
#### Github
- https://github.com/12442RF/POC
- https://github.com/DMW11525708/wiki
- https://github.com/Lern0n/Lernon-POC
- https://github.com/Linxloop/fork_POC
- https://github.com/adysec/POC
- https://github.com/eeeeeeeeee-code/POC
- https://github.com/greenberglinken/2023hvv_1
- https://github.com/iemotion/POC
- https://github.com/laoa1573/wy876
- https://github.com/oLy0/Vulnerability
- https://github.com/plbplbp/loudong001