Show filters
34 Total Results
Displaying 1-10 of 34
Sort by:
Attacker Value
Unknown
CVE-2021-37446
Disclosure Date: July 25, 2021 (last updated February 23, 2025)
In NCH Quorum v2.03 and earlier, an authenticated user can use directory traversal via documentprop?file=/.. for file reading.
0
Attacker Value
Unknown
CVE-2021-37442
Disclosure Date: July 25, 2021 (last updated February 23, 2025)
NCH IVM Attendant v5.12 and earlier allows path traversal via viewfile?file=/.. to read files.
0
Attacker Value
Unknown
CVE-2021-37445
Disclosure Date: July 25, 2021 (last updated February 23, 2025)
In NCH Quorum v2.03 and earlier, an authenticated user can use directory traversal via logprop?file=/.. for file reading.
0
Attacker Value
Unknown
CVE-2021-37444
Disclosure Date: July 25, 2021 (last updated February 23, 2025)
NCH IVM Attendant v5.12 and earlier suffers from a directory traversal weakness upon uploading plugins in a ZIP archive. This can lead to code execution if a ZIP element's pathname is set to a Windows startup folder, a file for the inbuilt Out-Going Message function, or a file for the the inbuilt Autodial function.
0
Attacker Value
Unknown
CVE-2021-37449
Disclosure Date: July 25, 2021 (last updated February 23, 2025)
Cross Site Scripting (XSS) exists in NCH IVM Attendant v5.12 and earlier via /ogmlist?folder= (reflected).
0
Attacker Value
Unknown
CVE-2021-37443
Disclosure Date: July 25, 2021 (last updated February 23, 2025)
NCH IVM Attendant v5.12 and earlier allows path traversal via the logdeleteselected check0 parameter for file deletion.
0
Attacker Value
Unknown
CVE-2021-37447
Disclosure Date: July 25, 2021 (last updated February 23, 2025)
In NCH Quorum v2.03 and earlier, an authenticated user can use directory traversal via documentdelete?file=/.. for file deletion.
0
Attacker Value
Unknown
CVE-2021-37448
Disclosure Date: July 25, 2021 (last updated February 23, 2025)
Cross Site Scripting (XSS) exists in NCH IVM Attendant v5.12 and earlier via the Mailbox name (stored).
0
Attacker Value
Unknown
CVE-2021-37470
Disclosure Date: July 25, 2021 (last updated February 23, 2025)
In NCH WebDictate v2.13, persistent Cross Site Scripting (XSS) exists in the Recipient Name field. An authenticated user can add or modify the affected field to inject arbitrary JavaScript.
0
Attacker Value
Unknown
CVE-2021-37461
Disclosure Date: July 25, 2021 (last updated February 23, 2025)
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via /extensionsinstruction?id= (reflected).
0