Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m4jr-2x8w-p434

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

cgi-bin/cgiServer.exx in Yealink VoIP Phone SIP-T38G allows remote authenticated users to execute arbitrary commands by calling the system method in the body of a request, as demonstrated by running unauthorized services, changing directory permissions, and modifying files.

cgi-bin/cgiServer.exx in Yealink VoIP Phone SIP-T38G allows remote authenticated users to execute arbitrary commands by calling the system method in the body of a request, as demonstrated by running unauthorized services, changing directory permissions, and modifying files.

EPSS

Процентиль: 93%
0.10706
Средний

Дефекты

CWE-78

Связанные уязвимости

nvd
больше 11 лет назад

cgi-bin/cgiServer.exx in Yealink VoIP Phone SIP-T38G allows remote authenticated users to execute arbitrary commands by calling the system method in the body of a request, as demonstrated by running unauthorized services, changing directory permissions, and modifying files.

EPSS

Процентиль: 93%
0.10706
Средний

Дефекты

CWE-78