Lucene search

K

Phone System Security Vulnerabilities

cve
cve

CVE-2023-20221

A vulnerability in the web-based management interface of Cisco IP Phone 6800, 7800, and 8800 Series with Multiplatform Firmware could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack against a user of the web-based management interface of an affected.....

6.5CVSS

6.6AI Score

0.001EPSS

2023-08-16 10:15 PM
28
cve
cve

CVE-2023-1275

A vulnerability classified as problematic was found in SourceCodester Phone Shop Sales Managements System 1.0. This vulnerability affects unknown code of the file /osms/assets/plugins/jquery-validation-1.11.1/demo/captcha/index.php of the component CAPTCHA Handler. The manipulation leads to cross.....

6.1CVSS

6.1AI Score

0.001EPSS

2023-03-08 06:15 PM
26
cve
cve

CVE-2019-9971

PhoneSystem Terminal in 3CX Phone System (Debian based installation) 16.0.0.1570 allows an attacker to gain root privileges by using sudo with the tcpdump command, without a password. This occurs because the -z (aka postrotate-command) option to tcpdump can be unsafe when used in conjunction with.....

8.8CVSS

8.7AI Score

0.003EPSS

2022-06-07 06:15 PM
31
2
cve
cve

CVE-2019-9972

PhoneSystem Terminal in 3CX Phone System (Debian based installation) 16.0.0.1570 allows an authenticated attacker to run arbitrary commands with the phonesystem user privileges because of " followed by "...

8.8CVSS

8.6AI Score

0.001EPSS

2022-06-07 06:15 PM
27
2
cve
cve

CVE-2022-20774

A vulnerability in the web-based management interface of Cisco IP Phone 6800, 7800, and 8800 Series with Multiplatform Firmware could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack against a user of the web-based interface of an affected system....

8.1CVSS

8.1AI Score

0.001EPSS

2022-04-06 07:15 PM
62
cve
cve

CVE-2021-45968

An issue was discovered in xmppserver jar in the XMPP Server component of the JIve platform, as used in Pascom Cloud Phone System before 7.20.x (and in other products). An endpoint in the backend Tomcat server of the Pascom allows SSRF, a related issue to...

7.5CVSS

8.3AI Score

0.607EPSS

2022-03-18 05:15 AM
1124
cve
cve

CVE-2021-45967

An issue was discovered in Pascom Cloud Phone System before 7.20.x. A configuration error between NGINX and a backend Tomcat server leads to a path traversal in the Tomcat server, exposing unintended...

9.8CVSS

9.3AI Score

0.676EPSS

2022-03-18 05:15 AM
1711
cve
cve

CVE-2021-45966

An issue was discovered in Pascom Cloud Phone System before 7.20.x. In the management REST API, /services/apply in exd.pl allows remote attackers to execute arbitrary code via shell...

9.8CVSS

9.7AI Score

0.039EPSS

2022-03-18 05:15 AM
1842
cve
cve

CVE-2021-3720

An information disclosure vulnerability was reported in the Time Weather system widget on Legion Phone Pro (L79031) and Legion Phone2 Pro (L70081) that could allow other applications to access device GPS...

5.5CVSS

5.2AI Score

0.0004EPSS

2021-11-12 10:15 PM
22
cve
cve

CVE-2021-36560

Phone Shop Sales Managements System using PHP with Source Code 1.0 is vulnerable to authentication bypass which leads to account takeover of the...

9.8CVSS

9.7AI Score

0.003EPSS

2021-11-02 10:15 AM
20
cve
cve

CVE-2021-34711

A vulnerability in the debug shell of Cisco IP Phone software could allow an authenticated, local attacker to read any file on the device file system. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by providing crafted input to a debug...

5.5CVSS

5.2AI Score

0.0004EPSS

2021-10-06 08:15 PM
22
cve
cve

CVE-2021-36623

Arbitrary File Upload in Sourcecodester Phone Shop Sales Management System 1.0 enables...

9.8CVSS

9.4AI Score

0.025EPSS

2021-08-03 06:15 PM
24
3
cve
cve

CVE-2021-36624

Sourcecodester Phone Shop Sales Managements System version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication...

9.8CVSS

9.9AI Score

0.004EPSS

2021-07-30 02:15 PM
35
7
cve
cve

CVE-2021-35337

Sourcecodester Phone Shop Sales Managements System 1.0 is vulnerable to Insecure Direct Object Reference (IDOR). Any attacker will be able to see the invoices of different users by changing the id...

4.3CVSS

4.5AI Score

0.003EPSS

2021-07-01 02:15 PM
34
cve
cve

CVE-2019-16008

A vulnerability in the web-based GUI of Cisco IP Phone 6800, 7800, and 8800 Series with Multiplatform Firmware could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based interface of an affected system. The vulnerability is due to...

5.4CVSS

5.2AI Score

0.001EPSS

2020-01-26 05:15 AM
113
cve
cve

CVE-2019-1766

A vulnerability in the web-based management interface of Session Initiation Protocol (SIP) Software for Cisco IP Phone 8800 Series could allow an unauthenticated, remote attacker to cause high disk utilization, resulting in a denial of service (DoS) condition. The vulnerability exists because the.....

7.5CVSS

7.6AI Score

0.002EPSS

2019-03-22 08:29 PM
31
cve
cve

CVE-2018-0461

A vulnerability in the Cisco IP Phone 8800 Series Software could allow an unauthenticated, remote attacker to conduct an arbitrary script injection attack on an affected device. The vulnerability exists because the software running on an affected device insufficiently validates user-supplied data.....

8.8CVSS

8.8AI Score

0.002EPSS

2019-01-10 04:29 PM
25
cve
cve

CVE-2012-6626

SQL injection vulnerability in verify-user.php in b2ePMS 1.0 allows remote attackers to execute arbitrary SQL commands via the username...

8.7AI Score

0.003EPSS

2014-01-16 09:55 PM
16
cve
cve

CVE-2012-5445

The kernel in Cisco Native Unix (CNU) on Cisco Unified IP Phone 7900 series devices (aka TNP phones) with software before 9.3.1-ES10 does not properly validate unspecified system calls, which allows attackers to execute arbitrary code or cause a denial of service (memory overwrite) via a crafted...

7.6AI Score

0.0004EPSS

2012-12-28 11:48 AM
24
cve
cve

CVE-2008-6896

login.php in 3CX Phone System 6.0.806.0, when 100% disk capacity is reached, allows remote attackers to gain sensitive information via unspecified vectors that reveal the installation...

6.6AI Score

0.002EPSS

2009-08-03 06:30 PM
21
cve
cve

CVE-2008-6894

Multiple cross-site scripting (XSS) vulnerabilities in login.php in 3CX Phone System Free Edition 6.1793 and 6.0.806.0 allow remote attackers to inject arbitrary web script or HTML via the (1) fName and (2) fPassword...

5.9AI Score

0.003EPSS

2009-08-03 06:30 PM
29
cve
cve

CVE-2008-6895

3CX Phone System 6.0.806.0 allows remote attackers to cause a denial of service (unstable service or crash) via unspecified vectors, as demonstrated by vulnerability scans from Nessus or...

7AI Score

0.003EPSS

2009-08-03 06:30 PM
24
cve
cve

CVE-2005-3717

The telnet daemon in UTStarcom F1000 VOIP WIFI Phone s2.0 running VxWorks 5.5.1 with kernel WIND 2.6 has a default username "target" and password "password", which allows remote attackers to gain full access to the...

7.4AI Score

0.011EPSS

2005-11-21 11:03 AM
25
cve
cve

CVE-2005-3722

The SNMP v1/v2c daemon in Hitachi IP5000 VOIP WIFI Phone 1.5.6 allows remote attackers to gain read or write access to system configuration using arbitrary SNMP...

7.4AI Score

0.012EPSS

2005-11-21 11:03 AM
19