Xpressa CVE-2002-0670 Remote Security Vulnerability

Xpressa is prone to a remote security vulnerability. The web interface for Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 uses Base64 encoded usernames and passwords for HTTP basic authentication, which allows remote attackers to steal and easily decode the passwords via sniffing.


 

Privacy Statement
Copyright 2010, SecurityFocus