Palosanto's vulnerability footprint centers on Elastix, a narrowly scoped unified communications and telephony platform, with the durable signal rooted in application-layer input-handling weaknesses including path traversal and SQL injection. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Palosanto over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2015-1875HIGH SQL injection vulnerability in a2billing/customer/iridium_threed.php in Elastix 2.5.0 and earlier allows remote attackers to execute arbitrary SQL commands via the transactionID pa | Mar 11, 2015 | 7.5 | 28 | NO | YES |
CVE-2010-1492MEDIUM Directory traversal vulnerability in help/frameRight.php in Elastix 1.6.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the id_nodo parameter. NOTE: the pr | Apr 23, 2010 | 5.0 | 16 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Palosanto.
Media articles that mention a CVE ID that affects a product developed by Palosanto — matched by CVE ID, not by vendor name.