• Skip to primary navigation
  • Skip to main content
CVE Vulnerability

CVE Vulnerability

  • CVE’s
  • Products
  • Vendors
Home » CVE’s

CVE’s


CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
CVE-2019-16988
2023-02-03
N/A
6.1 MEDIUM
In FusionPBX up to v4.5.7, the file appbasic_operator_panelresourcescontent.php uses an unsanitized "eavesdrop_dest" variable coming from the URL, which is reflected on 3 occasions in HTML, leading to XSS.
CVE-2019-16987
2023-02-03
N/A
6.1 MEDIUM
In FusionPBX up to v4.5.7, the file appcontactscontact_import.php uses an unsanitized "query_string" variable coming from the URL, which is reflected in HTML, leading to XSS.
CVE-2019-16986
2023-02-03
N/A
6.5 MEDIUM
In FusionPBX up to v4.5.7, the file resourcesdownload.php uses an unsanitized "f" variable coming from the URL, which takes any pathname and allows a download of it. (resourcessecure_download.php is also affected.)
CVE-2019-16985
2023-02-03
N/A
6.5 MEDIUM
In FusionPBX up to v4.5.7, the file appxml_cdrxml_cdr_delete.php uses an unsanitized "rec" variable coming from the URL, which is base64 decoded and allows deletion of any file of the system.
CVE-2019-16984
2023-02-03
N/A
6.1 MEDIUM
In FusionPBX up to v4.5.7, the file apprecordingsrecording_play.php uses an unsanitized "filename" variable coming from the URL, which is base64 decoded and reflected in HTML, leading to XSS.
CVE-2019-16983
2023-02-03
N/A
6.1 MEDIUM
In FusionPBX up to v4.5.7, the file resourcespaging.php has a paging function (called by several pages of the interface), which uses an unsanitized "param" variable constructed partially from the URL args and reflected in HTML, leading to XSS.
CVE-2019-16982
2023-02-03
N/A
6.1 MEDIUM
In FusionPBX up to v4.5.7, the file appaccess_controlsaccess_control_nodes.php uses an unsanitized "id" variable coming from the URL, which is reflected in HTML, leading to XSS.
CVE-2019-16981
2023-02-03
N/A
6.1 MEDIUM
In FusionPBX up to v4.5.7, the file appconference_profilesconference_profile_params.php uses an unsanitized "id" variable coming from the URL, which is reflected on 2 occasions in HTML, leading to XSS.
CVE-2019-16980
2023-02-03
N/A
8.8 HIGH
In FusionPBX up to v4.5.7, the file appcall_broadcastcall_broadcast_edit.php uses an unsanitized "id" variable coming from the URL in an unparameterized SQL query, leading to SQL injection.
CVE-2019-1698
2019-10-09
N/A
4.9 MEDIUM
A vulnerability in the web-based user interface of Cisco Internet of Things Field Network Director (IoT-FND) Software could allow an authenticated, remote attacker to gain read access to information that is stored on an affected system. The vulnerability is due to improper handling of XML External Entity (XXE) entries when parsing certain XML files. An attacker could exploit this vulnerability by importing a crafted XML file with malicious entries, which could allow the attacker to read files within the affected application. Versions prior to 4.4(0.26) are affected.
« Previous 1 … 5,980 5,981 5,982 5,983 5,984 … 11,258 Next »

Copyright CVE Vulnerabilities 2023
Data Sources:

  • NIST
  • MITRE
  • CVE Search
  • Open CVE