Skip to main content

Vendor archive

atcom CVEs

Beta · best-effort

7 CVEs tagged to vendor atcom1 Critical, 4 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2019-12328

Published Jul 22, 2019

A command injection (missing input validation) issue in the remote phonebook configuration URI in the web interface of the Atcom A10W VoIP phone with firmware 2.6.1a2421 allows an…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2014-2318

Published Mar 11, 2014

SQL injection vulnerability in ATCOM Netvolution 3 allows remote attackers to execute arbitrary SQL commands via the m parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2011-3340

Published Oct 21, 2011

SQL injection vulnerability in ATCOM Netvolution 2.5.8 ASP allows remote attackers to execute arbitrary SQL commands via the Referer HTTP header.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-4967

Published Oct 21, 2011

SQL injection vulnerability in default.asp in ATCOM Netvolution 2.5.6 allows remote attackers to execute arbitrary SQL commands via the artID parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-4966

Published Oct 21, 2011

Cross-site scripting (XSS) vulnerability in default.asp in ATCOM Netvolution allows remote attackers to inject arbitrary web script or HTML via the query parameter in a Search act…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-5103

Published Oct 21, 2011

Cross-site scripting (XSS) vulnerability in ATCOM Netvolution 1.0 ASP allows remote attackers to inject arbitrary web script or HTML via the email variable.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-5102

Published Oct 21, 2011

SQL injection vulnerability in default.asp in ATCOM Netvolution 1.0 ASP allows remote attackers to execute arbitrary SQL commands via the bpe_nid parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-7 of 7 CVEsPage 1 of 1