CVE-2018-11635
03.07.2018, 17:29
Use of a Hard-coded Cryptographic Key used to protect cookie session data in /var/www/xms/application/config/config.php in the administrative console in Dialogic PowerMedia XMS through 3.5 allows remote attackers to bypass authentication.Enginsight
Vendor | Product | Version |
---|---|---|
dialogic | powermedia_xms | 𝑥 ≤ 3.5 |
𝑥
= Vulnerable software versions