Vulnerabilities (CVE)

Filtered by vendor Multitech Subscribe
Filtered by product Faxfinder
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-17562 1 Multitech 1 Faxfinder 2023-12-10 5.0 MEDIUM 7.5 HIGH
Multi-Tech FaxFinder before 5.1.6 has SQL Injection via a status/call_details?oid= URI, allowing an attacker to extract the underlying database schema to further disclose other fax server information through different injection points.
CVE-2016-10512 1 Multitech 1 Faxfinder 2023-12-10 10.0 HIGH 9.8 CRITICAL
MultiTech FaxFinder before 4.1.2 stores Passwords unencrypted for maintaining the test connectivity function of its LDAP configuration. These credentials are retrieved by the system when the LDAP configuration page is opened and are embedded directly into the HTML source code in cleartext.