atcom records
7 published records for vendor atcom.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 4
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')4
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
7 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
36Monitor | CVE-2019-12328No exploit | A command injection (missing input validation) issue in the remote phonebook configuration URI in the web interface of the Atcom A10W VoIP patcom · a10w firmware · CWE-78 | High8.8 | — | 4.2% | Jul 22, 2019 |
31Monitor | CVE-2009-5102Proof of concept | SQL injection vulnerability in default.asp in ATCOM Netvolution 1.0 ASP allows remote attackers to execute arbitrary SQL commands via the bpatcom · netvolution · CWE-89 | High7.5 | — | 2.2% | Oct 21, 2011 |
31Monitor | CVE-2010-4967Proof of concept | SQL injection vulnerability in default.asp in ATCOM Netvolution 2.5.6 allows remote attackers to execute arbitrary SQL commands via the artIatcom · netvolution · CWE-89 | High7.5 | — | 2.0% | Oct 21, 2011 |
31Monitor | CVE-2014-2318No exploit | SQL injection vulnerability in ATCOM Netvolution 3 allows remote attackers to execute arbitrary SQL commands via the m parameter.atcom · netvolution · CWE-89 | High7.5 | — | 2.0% | Mar 11, 2014 |
31Monitor | CVE-2011-3340Proof of concept | SQL injection vulnerability in ATCOM Netvolution 2.5.8 ASP allows remote attackers to execute arbitrary SQL commands via the Referer HTTP heatcom · netvolution · CWE-89 | High7.5 | — | 2.0% | Oct 21, 2011 |
18Monitor | CVE-2009-5103Proof of concept | Cross-site scripting (XSS) vulnerability in ATCOM Netvolution 1.0 ASP allows remote attackers to inject arbitrary web script or HTML via theatcom · netvolution · CWE-79 | Medium4.3 | — | 2.6% | Oct 21, 2011 |
17Monitor | CVE-2010-4966No exploit | Cross-site scripting (XSS) vulnerability in default.asp in ATCOM Netvolution allows remote attackers to inject arbitrary web script or HTML atcom · netvolution · CWE-79 | Medium4.3 | — | 1.5% | Oct 21, 2011 |
- CVE-2019-1232836Monitor
A command injection (missing input validation) issue in the remote phonebook configuration URI in the web interface of the Atcom A10W VoIP p
HighCVSS 8.8No exploitEPSS 4%atcom · a10w firmwareJul 22, 2019
- CVE-2009-510231Monitor
SQL injection vulnerability in default.asp in ATCOM Netvolution 1.0 ASP allows remote attackers to execute arbitrary SQL commands via the bp
HighCVSS 7.5Proof of conceptEPSS 2%atcom · netvolutionOct 21, 2011
- CVE-2010-496731Monitor
SQL injection vulnerability in default.asp in ATCOM Netvolution 2.5.6 allows remote attackers to execute arbitrary SQL commands via the artI
HighCVSS 7.5Proof of conceptEPSS 2%atcom · netvolutionOct 21, 2011
- CVE-2014-231831Monitor
SQL injection vulnerability in ATCOM Netvolution 3 allows remote attackers to execute arbitrary SQL commands via the m parameter.
HighCVSS 7.5No exploitEPSS 2%atcom · netvolutionMar 11, 2014
- CVE-2011-334031Monitor
SQL injection vulnerability in ATCOM Netvolution 2.5.8 ASP allows remote attackers to execute arbitrary SQL commands via the Referer HTTP he
HighCVSS 7.5Proof of conceptEPSS 2%atcom · netvolutionOct 21, 2011
- CVE-2009-510318Monitor
Cross-site scripting (XSS) vulnerability in ATCOM Netvolution 1.0 ASP allows remote attackers to inject arbitrary web script or HTML via the
MediumCVSS 4.3Proof of conceptEPSS 3%atcom · netvolutionOct 21, 2011
- CVE-2010-496617Monitor
Cross-site scripting (XSS) vulnerability in default.asp in ATCOM Netvolution allows remote attackers to inject arbitrary web script or HTML
MediumCVSS 4.3No exploitEPSS 1%atcom · netvolutionOct 21, 2011