Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
nch axon pbx vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2009-4038
Multiple cross-site scripting (XSS) vulnerabilities in NCH Software Axon Virtual PBX 2.10 and 2.11 allow remote malicious users to inject arbitrary web script or HTML via the (1) onok or (2) oncancel parameter to the logon program. NOTE: the provenance of this information is unkn...
Nch Axon Virtual Pbx 2.10
Nch Axon Virtual Pbx 2.11
6.5
CVSSv3
CVE-2021-37440
NCH Axon PBX v2.22 and previous versions allows path traversal for file disclosure via the logprop?file=/.. substring.
Nch Axon Pbx
8.8
CVSSv3
CVE-2021-37441
NCH Axon PBX v2.22 and previous versions allows path traversal for file deletion via the logdelete?file=/.. substring.
Nch Axon Pbx
6.1
CVSSv3
CVE-2018-11552
There is a reflected XSS vulnerability in AXON PBX 2.02 via the "AXON->Auto-Dialer->Agents->Name" field. The vulnerability exists due to insufficient filtration of user-supplied data. A remote attacker can execute arbitrary HTML and script code in a browser in ...
Nch Axon Pbx 2.02
7.8
CVSSv3
CVE-2018-11551
AXON PBX 2.02 contains a DLL hijacking vulnerability that could allow an unauthenticated, remote malicious user to execute arbitrary code on a targeted system. The vulnerability exists because a DLL file is loaded by 'pbxsetup.exe' improperly.
Nch Axon Pbx 2.02
5.4
CVSSv3
CVE-2021-37461
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and previous versions via /extensionsinstruction?id= (reflected).
Nchsoftware Axon Pbx
5.4
CVSSv3
CVE-2021-37460
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and previous versions via /planprop?id= (reflected).
Nchsoftware Axon Pbx
5.4
CVSSv3
CVE-2021-37462
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and previous versions via /ipblacklist?errorip= (reflected).
Nchsoftware Axon Pbx
5.4
CVSSv3
CVE-2021-37453
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and previous versions via the extension name (stored).
Nchsoftware Axon Pbx
5.4
CVSSv3
CVE-2021-37457
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and previous versions via the SipRule field (stored).
Nchsoftware Axon Pbx
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-27322
CVE-2006-4304
wireless
CVE-2023-23022
local file inclusion
CVE-2024-27058
CVE-2024-33820
open redirect
CVE-2024-27079
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »