Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Fonality (previously trixbox Pro) 12.6 through 14.1i before 2016-06-01 has a hardcoded password for the FTP account, which allows remote attackers to obtain access via a (1) FTP or (2) SSH connection.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Fonality FTP 安全漏洞
Vulnerability Description
Fonality(前称Trixbox pro)是美国Fonality公司的一套集成VoIP和CRM功能的开源电话交换机解决方案。该方案支持语音信箱、多方语音会议和交互式语音应答(IVR)等。 Fonality 12.6版本至14.1i版本的FTP中存在安全漏洞,该漏洞源于程序使用硬编码的用户名和密码。远程攻击者可借助FTP或SSH连接利用该漏洞以‘nobody’身份登录并获取访问权限。
CVSS Information
N/A
Vulnerability Type
N/A