Vulnerabilities (CVE)

Filtered by vendor Dialogic Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-11635 1 Dialogic 1 Powermedia Xms 2020-08-24 7.5 HIGH 9.8 CRITICAL
Use of a Hard-coded Cryptographic Key used to protect cookie session data in /var/www/xms/application/config/config.php in the administrative console in Dialogic PowerMedia XMS through 3.5 allows remote attackers to bypass authentication.
CVE-2018-11640 1 Dialogic 1 Powermedia Xms 2018-09-07 6.4 MEDIUM 9.1 CRITICAL
XML External Entity (XXE) vulnerability in the web service in Dialogic PowerMedia XMS before 3.5 SU2 allows remote attackers to read arbitrary files or cause a denial of service (resource consumption).
CVE-2018-11641 1 Dialogic 1 Powermedia Xms 2018-09-04 7.5 HIGH 9.8 CRITICAL
Use of Hard-coded Credentials in /var/www/xms/application/controllers/gatherLogs.php in the administrative console in Dialogic PowerMedia XMS through 3.5 allows remote attackers to interact with a web service.