Avaya Communication Manager Web Interface Multiple Input Validation Vulnerabilities
BID:28684
Info
Avaya Communication Manager Web Interface Multiple Input Validation Vulnerabilities
| Bugtraq ID: | 28684 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 08 2008 12:00AM |
| Updated: | Apr 16 2008 12:28AM |
| Credit: | VoIPsheild |
| Vulnerable: |
Avaya Communication Manager 4.0 Avaya Communication Manager 3.1 |
| Not Vulnerable: | |
Discussion
Avaya Communication Manager Web Interface Multiple Input Validation Vulnerabilities
Avaya Communication Manager is prone to multiple input-validation vulnerabilities because the application fails to sufficiently sanitize user-supplied input.
An attacker can exploit these issues to execute arbitrary code and commands with superuser privleges, delete arbitrary system files, and obtain sensitive information. Successfully exploiting some of these issue will result in the complete compromise of affected computers.
These issues affect Avaya Communication Manager 3.1.x and 4.x; other versions may also be affected.
Avaya Communication Manager is prone to multiple input-validation vulnerabilities because the application fails to sufficiently sanitize user-supplied input.
An attacker can exploit these issues to execute arbitrary code and commands with superuser privleges, delete arbitrary system files, and obtain sensitive information. Successfully exploiting some of these issue will result in the complete compromise of affected computers.
These issues affect Avaya Communication Manager 3.1.x and 4.x; other versions may also be affected.
Exploit / POC
Solution / Fix
Avaya Communication Manager Web Interface Multiple Input Validation Vulnerabilities
Solution:
The vendor has released updates to address these issues. Please see the references for more information.
Solution:
The vendor has released updates to address these issues. Please see the references for more information.
References
Avaya Communication Manager Web Interface Multiple Input Validation Vulnerabilities
References:
References:
- Avaya Homepage (Avaya Inc.)
- IM SMS Arbitrary File Deletion (VoIPshield)
- IM SMS File Existence Flaw (VoIPshield)
- IM SMS Hostname Privilege Elevation (VoIPshield)
- IM SMS Route Privilege Elevation (VoIPshield)
- IM SMS System Time Code Execution (VoIPshield)
- Avaya Security Advisory ASA-2008-148 (Avaya)
- IM SMS Ping Code Execution (VoIPshield)