CVE-2008-1250 Information

Description

Multiple cross-site request forgery (CSRF) vulnerabilities in the web interface on the central phone server for the Snom 320 SIP Phone allow remote attackers to perform actions as the phone user as demonstrated by inserting an address-book entry containing an XSS sequence.

Reference

http://secunia.com/advisories/28938 http://www.gnucitizen.org/projects/router-hacking-challenge/ http://www.securityfocus.com/archive/1/489009/100/0/threaded http://www.securityfocus.com/bid/27767 https://exchange.xforce.ibmcloud.com/vulnerabilities/40500

Share on: