Vulnerabilities > Alcatel Lucent > Low

DATE CVE VULNERABILITY TITLE RISK
2017-03-23 CVE-2015-8687 Cross-site Scripting vulnerability in Alcatel-Lucent Motive Home Device Manager
Multiple cross-site scripting (XSS) vulnerabilities in the Management Console in Alcatel-Lucent Motive Home Device Manager (HDM) before 4.2 allow remote attackers to inject arbitrary web script or HTML via the (1) deviceTypeID parameter to DeviceType/getDeviceType.do; the (2) policyActionClass or (3) policyActionName parameter to PolicyAction/findPolicyActions.do; the deviceID parameter to (4) SingleDeviceMgmt/getDevice.do or (5) device/editDevice.do; the operation parameter to (6) ajax.do or (7) xmlHttp.do; or the (8) policyAction, (9) policyClass, or (10) policyName parameter to policy/findPolicies.do.
3.5
2011-03-08 CVE-2011-0345 Path Traversal vulnerability in Alcatel-Lucent Omnivista 4760R5.0.07.05
Directory traversal vulnerability in the NMS server in Alcatel-Lucent OmniVista 4760 R5.1.06.03 and earlier allows remote attackers to read arbitrary files via directory traversal sequences in HTTP GET requests, related to the lang variable.
low complexity
alcatel-lucent CWE-22
3.3
2002-05-31 CVE-2002-0294 Denial Of Service vulnerability in Alcatel-Lucent Omnipcx 4400
Alcatel 4400 installs the /chetc/shutdown command with setgid privileges, which allows many different local users to shut down the system.
local
low complexity
alcatel-lucent
2.1