Web Access component for COM2001 Alexis 2.0 and 2.1 in InternetPBX sends username and voice mail passwords in the clear via a Java applet that sends the information to port 8888 of the server, which could allow remote attackers to steal the passwords via sniffing.
References
Link | Resource |
---|---|
http://online.securityfocus.com/archive/1/217200 | Patch Vendor Advisory |
http://www.securityfocus.com/bid/3373 |
Configurations
Configuration 1 (hide)
|
Information
Published : 2001-09-26 21:00
Updated : 2008-09-10 12:10
NVD link : CVE-2001-1254
Mitre link : CVE-2001-1254
JSON object : View
CWE
Products Affected
com2001
- alexis_server