VendorsDialogicpowermedia_xms3.5
Vulnerabilities

Dialogic PowerMedia XMS 3.5

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2018-11639
Plaintext Storage of Passwords within Cookies in /var/www/xms/application/controllers/verifyLogin.php in the administrative console in Dialogic PowerMedia XMS before 3.5 SU2 allows remote attackers to access a user's password in cleartext.
Published 2018-07-03 · Modified
8.1EPSS 0.011
CVE-2018-11634
Plaintext Storage of Passwords in the administrative console in Dialogic PowerMedia XMS before 3.5 SU2 allows local users to access the web application's user passwords in cleartext by reading /var/www/xms/xmsdb/default.db.
Published 2018-07-03 · Modified
7.8EPSS 0.004