Show filters
461 Total Results
Displaying 231-240 of 461
Sort by:
Attacker Value
Unknown
CVE-2018-6635
Disclosure Date: February 05, 2018 (last updated November 26, 2024)
System Manager in Avaya Aura before 7.1.2 does not properly use SSL in conjunction with authentication, which allows remote attackers to bypass intended Remote Method Invocation (RMI) restrictions, aka SMGR-26896.
0
Attacker Value
Unknown
CVE-2017-18024
Disclosure Date: January 10, 2018 (last updated November 26, 2024)
AvantFAX 3.3.3 has XSS via an arbitrary parameter name to the default URI, as demonstrated by a parameter whose name contains a SCRIPT element and whose value is 1.
0
Attacker Value
Unknown
CVE-2017-1000467
Disclosure Date: January 03, 2018 (last updated November 26, 2024)
LavaLite version 5.2.4 is vulnerable to stored cross-site scripting vulnerability, within the blog creation page, which can result in disruption of service and execution of javascript code.
0
Attacker Value
Unknown
CVE-2017-16733
Disclosure Date: December 20, 2017 (last updated November 26, 2024)
A SQL Injection issue was discovered in Ecava IntegraXor v 6.1.1030.1 and prior. The SQL Injection vulnerability has been identified, which an attacker can leverage to disclose sensitive information from the database.
0
Attacker Value
Unknown
CVE-2017-16735
Disclosure Date: December 20, 2017 (last updated November 26, 2024)
A SQL Injection issue was discovered in Ecava IntegraXor v 6.1.1030.1 and prior. The SQL Injection vulnerability has been identified, which generates an error in the database log.
0
Attacker Value
Unknown
CVE-2017-12969
Disclosure Date: November 10, 2017 (last updated November 08, 2023)
Buffer overflow in the ViewerCtrlLib.ViewerCtrl ActiveX control in Avaya IP Office Contact Center before 10.1.1 allows remote attackers to cause a denial of service (heap corruption and crash) or execute arbitrary code via a long string to the open method.
0
Attacker Value
Unknown
CVE-2017-11309
Disclosure Date: November 10, 2017 (last updated November 08, 2023)
Buffer overflow in the SoftConsole client in Avaya IP Office before 10.1.1 allows remote servers to execute arbitrary code via a long response.
0
Attacker Value
Unknown
CVE-2017-14003
Disclosure Date: October 11, 2017 (last updated November 26, 2024)
An Authentication Bypass by Spoofing issue was discovered in LAVA Ether-Serial Link (ESL) running firmware versions 6.01.00/29.03.2007 and prior versions. An improper authentication vulnerability has been identified, which, if exploited, would allow an attacker with the same IP address to bypass authentication by accessing a specific uniform resource locator.
0
Attacker Value
Unknown
CVE-2017-1000065
Disclosure Date: July 17, 2017 (last updated November 26, 2024)
Multiple Cross-site scripting (XSS) vulnerabilities in rpc.php in OpenMediaVault release 2.1 in Access Rights Management(Users) functionality allows attackers to inject arbitrary web scripts and execute malicious scripts within an authenticated client's browser.
0
Attacker Value
Unknown
CVE-2017-6050
Disclosure Date: June 21, 2017 (last updated November 26, 2024)
A SQL Injection issue was discovered in Ecava IntegraXor Versions 5.2.1231.0 and prior. The application fails to properly validate user input, which may allow for an unauthenticated attacker to remotely execute arbitrary code in the form of SQL queries.
0