>> Avaya Message Storage Server Arbitrary Code Execution Vulnerabilities
Title : Avaya Message Storage Server Arbitrary Code Execution Vulnerabilities VUPEN ID : VUPEN/ADV-2008-1945 CVE ID : CVE-2008-3081 CWE ID : CWE-20
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-06-27
Technical Description
Multiple vulnerabilities have been identified in Avaya Message Storage Server (MSS), which could be exploited by malicious users to compromise a vulnerable system. These issues are caused by input validation errors in the Web management interface when processing user-supplied data, which could allow authenticated attackers to execute arbitrary code.