[VOIPSEC] Help in finding more information about recent SIP vulnerabilities

Ravi Chunduru ravivoipsa at gmail.com
Mon May 12 01:20:09 CDT 2008


Is there any place where I can find more information about following
vulnerabilities reported in OSVDB?  I am trying to create snort signatures
for these. I can't find any more information either in CVE,  bugtraq etc..

44284 <http://osvdb.org/show/osvdb/44284> 2008-04-09 Avaya SIP Enablement
Services (SES) SPIM Pages Unauthenticated Unspecified SQL Injection
 44285 <http://osvdb.org/show/osvdb/44285> 2008-04-09 Avaya SIP Enablement
Services (SES) SPIM Pages Unspecified SQL Injection
 44286 <http://osvdb.org/show/osvdb/44286> 2008-04-01 Avaya SIP Enablement
Services (SES) SIP REQUEST SQL Injection
 44287 <http://osvdb.org/show/osvdb/44287> 2008-04-01 Avaya SIP Enablement
Services (SES) Unspecified SQL Injection DoS
 44288 <http://osvdb.org/show/osvdb/44288> 2008-04-01 Avaya SIP Enablement
Services (SES) SIP Credential Replay
Thanks
Ravi



More information about the Voipsec mailing list