|
Cisco VoIP Phone Web Interface System Memory Contents Information Leakage Vulnerability
The 7900 series VoIP Phones are a Voice-Over-IP solution distributed by Cisco Systems. By placing a request to the /PortInformation script with a port ID (i.e. http://www.example.com/PortInformation?<port> where <port> is an integer value) of arbitrarily high value, the web server will return a dump of the contents of phone memory. This has been reportedly reproduced by passing port ID values of greater than 32768, and consistently reproduced with a value of 120000. |
|
|
Privacy Statement |