Vulnerabilities
Vulnerable Software
Nch:  Security Vulnerabilities
NCH FlexiServer v6.00 suffers from a syslog?file=/.. path traversal vulnerability.
CVSS Score
6.5
EPSS Score
0.004
Published
2021-07-25
NCH Axon PBX v2.22 and earlier allows path traversal for file disclosure via the logprop?file=/.. substring.
CVSS Score
6.5
EPSS Score
0.002
Published
2021-07-25
NCH Axon PBX v2.22 and earlier allows path traversal for file deletion via the logdelete?file=/.. substring.
CVSS Score
8.8
EPSS Score
0.005
Published
2021-07-25
NCH Reflect CRM 3.01 allows local users to discover cleartext user account information by reading the configuration files.
CVSS Score
3.3
EPSS Score
0.0
Published
2021-07-25
In NCH WebDictate v2.13 and earlier, authenticated users can abuse logprop?file=/.. path traversal to read files on the filesystem.
CVSS Score
6.5
EPSS Score
0.003
Published
2021-07-25
NCH Quorum v2.03 and earlier allows local users to discover cleartext login information relating to users by reading the local .dat configuration files.
CVSS Score
5.5
EPSS Score
0.0
Published
2021-07-25
AXON PBX 2.02 contains a DLL hijacking vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code on a targeted system. The vulnerability exists because a DLL file is loaded by 'pbxsetup.exe' improperly.
CVSS Score
7.8
EPSS Score
0.014
Published
2018-06-01
There is a reflected XSS vulnerability in AXON PBX 2.02 via the "AXON->Auto-Dialer->Agents->Name" field. The vulnerability exists due to insufficient filtration of user-supplied data. A remote attacker can execute arbitrary HTML and script code in a browser in the context of the vulnerable application.
CVSS Score
6.1
EPSS Score
0.003
Published
2018-06-01
Multiple cross-site scripting (XSS) vulnerabilities in NCH Software Axon Virtual PBX 2.10 and 2.11 allow remote attackers to inject arbitrary web script or HTML via the (1) onok or (2) oncancel parameter to the logon program. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CVSS Score
4.3
EPSS Score
0.003
Published
2009-11-20


Contact Us

Shodan ® - All rights reserved