5
CVSSv2

CVE-2005-0506

Published: 14/03/2005 Updated: 18/10/2016
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The Avaya IP Office Phone Manager, and other products such as the IP Softphone, stores sensitive data in cleartext in a registry key, which allows local and possibly remote users to steal usernames and passwords and impersonate other users via keys such as Avaya\IP400\Generic.

Vulnerable Product Search on Vulmon Subscribe to Product

avaya ip office phone manager

avaya ip soft phone

Exploits

#include <windowsh> #include <stdioh> #include <stringh> /* Filename: exploitc Title: Avaya IP Office Phone Manager - Cleartext Sensitive Data Vulnerability Exploit v001 Author: pagvac (Adrian Pastor) Date: 24th Feb, ...