Show filters
4 Total Results
Displaying 1-4 of 4
Sort by:
Attacker Value
Unknown
CVE-2014-3313
Disclosure Date: July 09, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the web user interface on Cisco Small Business SPA300 and SPA500 phones allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCuo52582.
0
Attacker Value
Unknown
CVE-2014-3312
Disclosure Date: July 09, 2014 (last updated October 05, 2023)
The debug console interface on Cisco Small Business SPA300 and SPA500 phones does not properly perform authentication, which allows local users to execute arbitrary debug-shell commands, or read or modify data in memory or a filesystem, via direct access to this interface, aka Bug ID CSCun77435.
0
Attacker Value
Unknown
CVE-2007-5411
Disclosure Date: October 12, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the Linksys SPA941 VoIP Phone with firmware 5.1.8 allows remote attackers to inject arbitrary web script or HTML via the From header in a SIP message.
0
Attacker Value
Unknown
CVE-2007-2270
Disclosure Date: April 25, 2007 (last updated October 04, 2023)
The Linksys SPA941 VoIP Phone allows remote attackers to cause a denial of service (device reboot) via a 0377 (0xff) character in the From header, and possibly certain other locations, in a SIP INVITE request.
0