Zoom VoIP Telephone Adapter Cross Site Request Forgery Vulnerability
BID:33528
Info
Zoom VoIP Telephone Adapter Cross Site Request Forgery Vulnerability
| Bugtraq ID: | 33528 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 29 2009 12:00AM |
| Updated: | Feb 02 2009 07:59PM |
| Credit: | Michael Brooks |
| Vulnerable: |
Zoom Zoom VoIP Telephone Adapter ATA1+1 1.2.5 |
| Not Vulnerable: | |
Discussion
Zoom VoIP Telephone Adapter Cross Site Request Forgery Vulnerability
Zoom VoIP Telephone Adapter is prone to a cross-site request-forgery vulnerability.
Exploiting this issue may allow a remote attacker to change the VoIP provider information and perform other unauthorized actions.
This issue affects Zoom VoIP Telephone Adapter ATA1+1 1.2.5; other versions may also be affected.
Zoom VoIP Telephone Adapter is prone to a cross-site request-forgery vulnerability.
Exploiting this issue may allow a remote attacker to change the VoIP provider information and perform other unauthorized actions.
This issue affects Zoom VoIP Telephone Adapter ATA1+1 1.2.5; other versions may also be affected.
Exploit / POC
Zoom VoIP Telephone Adapter Cross Site Request Forgery Vulnerability
To exploit this issue, an attacker must entice an unsuspecting victim into following a malicious URI.
The following exploit code is available:
To exploit this issue, an attacker must entice an unsuspecting victim into following a malicious URI.
The following exploit code is available:
Solution / Fix
Zoom VoIP Telephone Adapter Cross Site Request Forgery Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Zoom VoIP Telephone Adapter Cross Site Request Forgery Vulnerability
References:
References: