Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 downloads phone applications from a web site but can not verify the integrity of the applications, which could allow remote attackers to install Trojan horse applications via DNS spoofing.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Pingtel Expressa任意远程配置电话设置漏洞
Vulnerability Description
Expressa是一款由pingTel开发和维护的基于JAVA的VOIP电话系统。 Expressa电话系统使用的HTTP服务在验证机制中存在问题,远程攻击者可以利用这个漏洞配置电话设置。 Expressa电话系统提供WEB接口允许远程配置电话设置,WEB接口使用简单的HTTP basic方式验证:使用BASE64编码的用户名/密码对,攻击者可以利用这个漏洞执行安装和删除应用程序,查看和改动拨号设置和配置电话设置等操作。 <*链接:http://archives.neohapsis.com/archive
CVSS Information
N/A
Vulnerability Type
N/A