Show filters
70 Total Results
Displaying 51-60 of 70
Sort by:
Attacker Value
Unknown

CVE-2014-4855

Disclosure Date: July 10, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the Polylang plugin before 1.5.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via vectors related to a user description. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2012-4970

Disclosure Date: January 01, 2013 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the web management interface on Polycom HDX Video End Points with UC APL software before 2.7.1.1_J, and commercial software before 3.0.5, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown

CVE-2011-0423

Disclosure Date: January 12, 2011 (last updated October 04, 2023)
The PolyVision RoomWizard with firmware 3.2.3 has a default password of roomwizard for the administrator account, which makes it easier for remote attackers to obtain console access via an HTTP session, a different vulnerability than CVE-2010-0214.
0
Attacker Value
Unknown

CVE-2010-0214

Disclosure Date: January 12, 2011 (last updated October 04, 2023)
The administrative interface on the PolyVision RoomWizard with firmware 3.2.3 places the Sync Connector Active Directory (AD) credentials in a web form that is accessed over HTTP on port 80, which allows remote attackers to obtain sensitive information by reading the HTML source code corresponding to the /admin/sign/DeviceSynch URI.
0
Attacker Value
Unknown

CVE-2008-3505

Disclosure Date: August 06, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in PolyPager 1.0 rc2 and earlier allows remote attackers to inject arbitrary web script or HTML via the nr parameter to the default URI.
0
Attacker Value
Unknown

CVE-2008-3506

Disclosure Date: August 06, 2008 (last updated October 04, 2023)
SQL injection vulnerability in PolyPager 1.0 rc2 and earlier allows remote attackers to execute arbitrary SQL commands via the nr parameter to the default URI.
0
Attacker Value
Unknown

CVE-2008-1342

Disclosure Date: March 17, 2008 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in the search feature in Polymita BPM-Suite and CollagePortal allow remote attackers to inject arbitrary web script or HTML via the (1) _q and (2) lucene_index_field_value parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown

CVE-2007-3369

Disclosure Date: June 22, 2007 (last updated October 04, 2023)
Buffer overflow in the Polycom SoundPoint IP 601 SIP phone with BootROM 3.0.x+ and SIP version 1.6.3.0067 allows remote attackers to cause a denial of service (device hang or reboot) via an INVITE message with a long Via header.
0
Attacker Value
Unknown

CVE-2007-3368

Disclosure Date: June 22, 2007 (last updated October 04, 2023)
Buffer overflow in the HTTP server on the Polycom SoundPoint IP 601 SIP phone with BootROM 3.0.x+ allows remote attackers to cause a denial of service (device reboot) via a malformed CGI parameter.
0
Attacker Value
Unknown

CVE-2006-5233

Disclosure Date: October 11, 2006 (last updated October 04, 2023)
Polycom SoundPoint IP 301 VoIP Desktop Phone, firmware version 1.4.1.0040, allows remote attackers to cause a denial of service (reboot) via (1) a long URL sent to the HTTP daemon and (2) unspecified manipulations as demonstrated by the Nessus http_fingerprinting_hmap.nasl script.
0