CVE-2022-24629

CVE-2022-24629

An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. Remote code execution can be achieved via directory traversal in the dir parameter of the file upload functionality of BrowseFiles.php. An attacker can upload a .php file to WebAdmin/admin/AudioCodes_files/ajax/.

Source: CVE-2022-24629

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다