Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x75m-rrhq-6j68

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The web part of Zenitel AlphaCom XE Audio Server through 11.2.3.10, called AlphaWeb XE, does not restrict file upload in the Custom Scripts section at php/index.php. Neither the content nor extension of the uploaded files is checked, allowing execution of PHP code under the /cmd directory.

The web part of Zenitel AlphaCom XE Audio Server through 11.2.3.10, called AlphaWeb XE, does not restrict file upload in the Custom Scripts section at php/index.php. Neither the content nor extension of the uploaded files is checked, allowing execution of PHP code under the /cmd directory.

EPSS

Процентиль: 96%
0.26958
Средний

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 8.8
nvd
больше 4 лет назад

The web part of Zenitel AlphaCom XE Audio Server through 11.2.3.10, called AlphaWeb XE, does not restrict file upload in the Custom Scripts section at php/index.php. Neither the content nor extension of the uploaded files is checked, allowing execution of PHP code under the /cmd directory.

EPSS

Процентиль: 96%
0.26958
Средний

Дефекты

CWE-434