Vulnerabilities
Vulnerable Software
Atcom:  Security Vulnerabilities
A command injection (missing input validation) issue in the remote phonebook configuration URI in the web interface of the Atcom A10W VoIP phone with firmware 2.6.1a2421 allows an authenticated remote attacker in the same network to trigger OS commands via shell metacharacters in a POST request.
CVSS Score
9.0
EPSS Score
0.042
Published
2019-07-22
SQL injection vulnerability in ATCOM Netvolution 3 allows remote attackers to execute arbitrary SQL commands via the m parameter.
CVSS Score
7.5
EPSS Score
0.021
Published
2014-03-11
SQL injection vulnerability in default.asp in ATCOM Netvolution 1.0 ASP allows remote attackers to execute arbitrary SQL commands via the bpe_nid parameter.
CVSS Score
7.5
EPSS Score
0.023
Published
2011-10-21
Cross-site scripting (XSS) vulnerability in ATCOM Netvolution 1.0 ASP allows remote attackers to inject arbitrary web script or HTML via the email variable.
CVSS Score
4.3
EPSS Score
0.026
Published
2011-10-21
Cross-site scripting (XSS) vulnerability in default.asp in ATCOM Netvolution allows remote attackers to inject arbitrary web script or HTML via the query parameter in a Search action.
CVSS Score
4.3
EPSS Score
0.015
Published
2011-10-21
SQL injection vulnerability in default.asp in ATCOM Netvolution 2.5.6 allows remote attackers to execute arbitrary SQL commands via the artID parameter.
CVSS Score
7.5
EPSS Score
0.021
Published
2011-10-21
SQL injection vulnerability in ATCOM Netvolution 2.5.8 ASP allows remote attackers to execute arbitrary SQL commands via the Referer HTTP header.
CVSS Score
7.5
EPSS Score
0.02
Published
2011-10-21


Contact Us

Shodan ® - All rights reserved