Логотип exploitDog
bind:CVE-2022-24629
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-24629

Количество 2

Количество 2

nvd логотип

CVE-2022-24629

больше 2 лет назад

An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. Remote code execution can be achieved via directory traversal in the dir parameter of the file upload functionality of BrowseFiles.php. An attacker can upload a .php file to WebAdmin/admin/AudioCodes_files/ajax/.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-xc6r-22gr-xppq

больше 2 лет назад

An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. Remote code execution can be achieved via directory traversal in the dir parameter of the file upload functionality of BrowseFiles.php. An attacker can upload a .php file to WebAdmin/admin/AudioCodes_files/ajax/.

CVSS3: 9.8
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-24629

An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. Remote code execution can be achieved via directory traversal in the dir parameter of the file upload functionality of BrowseFiles.php. An attacker can upload a .php file to WebAdmin/admin/AudioCodes_files/ajax/.

CVSS3: 9.8
46%
Средний
больше 2 лет назад
github логотип
GHSA-xc6r-22gr-xppq

An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. Remote code execution can be achieved via directory traversal in the dir parameter of the file upload functionality of BrowseFiles.php. An attacker can upload a .php file to WebAdmin/admin/AudioCodes_files/ajax/.

CVSS3: 9.8
46%
Средний
больше 2 лет назад

Уязвимостей на страницу