Audiocodes Device Manager Express directory traversal | CVE-2022-24629
NAME
__________
Audiocodes Device Manager Express directory traversal
Platforms Affected:
Audiocodes Device Manager Express 7.8.20002.47752
Risk Level:
4.9
Exploitability:
Unproven
Consequences:
Gain Access
DESCRIPTION
__________
Audiocodes Device Manager Expresscould allow a remote authenticated attacker to traverse directories on the system. An attacker could send a specially-crafted URL request to the BrowseFiles.php script containing “dot dot” sequences (/../) to upload arbitrary files on the system, and leading to code execution.
CVSS 3.0 Information
__________
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Access Vector:
Network
A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.
If you like the site, please support us on Patreon using the button below

To keep up to date follow us on the below channels.



