Description: Avaya has acknowledged some vulnerabilities in PHP included in various Avaya products, which can be exploited by malicious users to cause a DoS (Denial of Service) or compromise a vulnerable system, and by malicious people to conduct cross-site scripting attacks, to gain knowledge of potentially sensitive information, and to use PHP as an open mail relay.
The following products are affected:
* Avaya S87XX/S8500/S8300 (2.x versions)
* Avaya Intuity LX (all versions)
* Avaya Message Networking (all versions)
Solution: Avaya S87XX/S8500/S8300:
Upgrade to version CM 3.0 or later.
Avaya Intuity LX, Avaya Message Networking:
The vendor recommends that local and network access to the affected systems should be restricted until an update is available.
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.