Articles tagged with: #sql-injection Clear filter
Heads Up: Scans for ESAFENET CDG V5 , (Mon, Oct 13th)

Heads Up: Scans for ESAFENET CDG V5 , (Mon, Oct 13th)

SANS Internet Storm Center, InfoCON: green isc.sans.edu

In January, a possible XSS vulnerability was found in the electronic document security management system ESAFENET CDG. This was the latest (as far as I can tell) in a long list of vulnerabilities in the product. Prior vulnerabilities included SQL injection issues and weaknesses in the encryption used to safeguard documents. In other words: A typical "secure" document management system. The product appears to be targeting the Chinese market, and with a website all in Chinese, I doubt it is used...