CVE-2008-6894: XSS
Published Aug 3, 2009
·Updated
Multiple cross-site scripting (XSS) vulnerabilities in login.php in 3CX Phone System Free Edition 6.1793 and 6.0.806.0 allow remote attackers to inject arbitrary web script or HTML via the (1) fName and (2) fPassword parameters.
Affected Software
2 affected components
3CX Phone System=6.0.806.0
3CX Phone System=6.1793
Event History
Aug 3, 2009
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-6894?
CVE-2008-6894 is considered a moderate severity vulnerability due to its cross-site scripting (XSS) capabilities.
2
How do I fix CVE-2008-6894?
To fix CVE-2008-6894, upgrade to a patched version of 3CX Phone System that addresses the XSS vulnerabilities.
3
What are the affected versions in CVE-2008-6894?
CVE-2008-6894 affects 3CX Phone System Free Edition versions 6.1793 and 6.0.806.0.
4
What type of vulnerability is CVE-2008-6894?
CVE-2008-6894 is classified as a cross-site scripting (XSS) vulnerability.
5
Can CVE-2008-6894 be exploited remotely?
Yes, CVE-2008-6894 can be exploited remotely by injecting arbitrary web script or HTML.