RSS   Vulnerabilities for '3cx web server'   RSS

2018-08-03
 
CVE-2018-14907

CWE-388
 

 
The Web server in 3CX version 15.5.8801.3 is vulnerable to Information Leakage, because of improper error handling in Stack traces, as demonstrated by discovering a full pathname.

 
 
CVE-2018-14906

CWE-79
 

 
The Web server in 3CX version 15.5.8801.3 is vulnerable to Reflected XSS on all stack traces' propertyPath parameters.

 
 
CVE-2018-14905

CWE-79
 

 
The Web server in 3CX version 15.5.8801.3 is vulnerable to Reflected XSS on the api/CallLog TimeZoneName parameter.

 

 >>> Vendor: 3CX 4 Products
Phone system
3CX
3cx web server
Wp-live chat


Copyright 2024, cxsecurity.com

 

Back to Top