10
CVSSv2

CVE-2008-1331

Published: 02/04/2008 Updated: 14/08/2019
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

cgi-data/FastJSData.cgi in OmniPCX Office with Internet Access services OXO210 prior to 210/091.001, OXO600 prior to 610/014.001, and other versions, allows remote malicious users to execute arbitrary commands and "obtain OXO resources" via shell metacharacters in the id2 parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

alcatel-lucent omnipcx office

Exploits

Digital Security Research Group [DSecRG] Advisory #DSECRG-08-020 Application: Alcatel OmniPCX Office Versions Affected: Alcatel OmniPCX Office since release 210/0611 Vendor URL: alcatelcom Bugs: Remote command execution Exploits: YES ...