Multiple unspecified "input validation" vulnerabilities in the Web management interface (aka Messaging Administration interface) in Avaya Message Storage Server (MSS) 3.x and 4.0, and possibly Communication Manager 3.1.x, allow remote authenticated administrators to execute arbitrary commands as user vexvm via vectors related to (1) SFTP Remote Store configuration; (2) remote FTP storage settings; (3) name server lookup; (4) pinging another host; (5) TCP/IP Networking parameter configuration; (6) the external hosts configuration main page; (7) adding and changing external hosts; (8) Windows domain parameter configuration; (9) date, time, and NTP server configuration; (10) alarm settings; (11) the command line history form; (12) the maintenance form; and (13) the server events form.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2008-07-09T00:00:00
Updated: 2024-08-07T09:21:35.011Z
Reserved: 2008-07-08T00:00:00
Link: CVE-2008-3081
Vulnrichment
No data.
NVD
Status : Modified
Published: 2008-07-09T00:41:00.000
Modified: 2024-11-21T00:48:23.333
Link: CVE-2008-3081
Redhat
No data.