Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xc6r-22gr-xppq

Опубликовано: 29 мая 2023
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. Remote code execution can be achieved via directory traversal in the dir parameter of the file upload functionality of BrowseFiles.php. An attacker can upload a .php file to WebAdmin/admin/AudioCodes_files/ajax/.

An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. Remote code execution can be achieved via directory traversal in the dir parameter of the file upload functionality of BrowseFiles.php. An attacker can upload a .php file to WebAdmin/admin/AudioCodes_files/ajax/.

EPSS

Процентиль: 98%
0.45658
Средний

9.8 Critical

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 9.8
nvd
больше 2 лет назад

An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. Remote code execution can be achieved via directory traversal in the dir parameter of the file upload functionality of BrowseFiles.php. An attacker can upload a .php file to WebAdmin/admin/AudioCodes_files/ajax/.

EPSS

Процентиль: 98%
0.45658
Средний

9.8 Critical

CVSS3

Дефекты

CWE-22