CVE-2019-9632
HIGH NUCLEIESAFENET CDG V3-V5 - File Download
Title source: llmDescription
ESAFENET CDG V3 and V5 has an arbitrary file download vulnerability via the fileName parameter in download.jsp because the InstallationPack parameter is mishandled in a /CDGServer3/ClientAjax request.
Nuclei Templates (1)
ESAFENET CDG - Arbitrary File Download
HIGHby pdteam
FOFA:
title="电子文档安全管理系统"
Scores
CVSS v3
7.5
EPSS
0.7923
EPSS Percentile
99.1%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Details
Status
published
Products (2)
esafenet/electronic_document_security_management_system
v3
esafenet/electronic_document_security_management_system
v5
Published
Mar 08, 2019
Tracked Since
Feb 18, 2026