Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2017-15359

Опубликовано: 18 окт. 2017
Источник: nvd
CVSS3: 6.5
CVSS2: 4
EPSS Низкий

Описание

In the 3CX Phone System 15.5.3554.1, the Management Console typically listens to port 5001 and is prone to a directory traversal attack: "/api/RecordingList/DownloadRecord?file=" and "/api/SupportInfo?file=" are the vulnerable parameters. An attacker must be authenticated to exploit this issue to access sensitive information to aid in subsequent attacks.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:3cx:3cx:15.5.3554.1:*:*:*:*:*:*:*

EPSS

Процентиль: 91%
0.06863
Низкий

6.5 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 6.5
github
больше 3 лет назад

In the 3CX Phone System 15.5.3554.1, the Management Console typically listens to port 5001 and is prone to a directory traversal attack: "/api/RecordingList/DownloadRecord?file=" and "/api/SupportInfo?file=" are the vulnerable parameters. An attacker must be authenticated to exploit this issue to access sensitive information to aid in subsequent attacks.

EPSS

Процентиль: 91%
0.06863
Низкий

6.5 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-22