Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%
Get alerts for future matching vulnerabilitiesLog in to subscribe
I. Basic Information for CVE-2018-0461
Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Cisco IP Phone 8800 Series Arbitrary Script Injection Vulnerability
Source: NVD (National Vulnerability Database)
Vulnerability Description
A vulnerability in the Cisco IP Phone 8800 Series Software could allow an unauthenticated, remote attacker to conduct an arbitrary script injection attack on an affected device. The vulnerability exists because the software running on an affected device insufficiently validates user-supplied data. An attacker could exploit this vulnerability by persuading a user to click a malicious link provided to the user or through the interface of an affected device. A successful exploit could allow an attacker to execute arbitrary script code in the context of the user interface or access sensitive system-based information, which under normal circumstances should be prohibited.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
对生成代码的控制不恰当(代码注入)
Source: NVD (National Vulnerability Database)
Vulnerability Title
Cisco IP Phone 8800 Series Software 代码注入漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Cisco IP Phone 8800 Series是美国思科(Cisco)公司的一款提供视频和VoIP通信功能的电话产品。Cisco IP Phone 8800 Series Software是运行在其中的一套软件。 Cisco IP Phone 8800 Series Software中存在代码注入漏洞,该漏洞源于程序没有充分验证用户提交的数据。远程攻击者可借助特制的链接利用该漏洞在用户界面的上下文中执行任意脚本代码或访问基于系统的敏感信息。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)
Affected Products
VendorProductAffected VersionsCPESubscribe
CiscoCisco IP Phone 8800 Series Software n/a -
II. Public POCs for CVE-2018-0461
#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC
III. Intelligence Information for CVE-2018-0461
Please Login to view more intelligence information
IV. Related Vulnerabilities
V. Comments for CVE-2018-0461

No comments yet


Leave a comment