PT-2012-5014 · Avaya · Avaya Ip Office Customer Call Reporter

Andrea Micalizzi

·

Publicado

2012-06-28

·

Atualizado

2012-07-17

·

CVE-2012-3811

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Avaya IP Office Customer Call Reporter versions 7.0 through 7.0.5.8 Avaya IP Office Customer Call Reporter versions 8.0 through 8.0.9.13
Description The issue concerns an unrestricted file upload vulnerability in the ImageUpload.ashx component of the Wallboard application. This allows remote attackers to execute arbitrary code by uploading an executable file and then accessing it via a direct request.
Recommendations For Avaya IP Office Customer Call Reporter versions 7.0 through 7.0.5.8, update to version 7.0.5.8 Q1 2012 Maintenance Release or later. For Avaya IP Office Customer Call Reporter versions 8.0 through 8.0.9.13, update to version 8.0.9.13 Q1 2012 Maintenance Release or later.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2012-3811
ZDI-12-106

Produtos afetados

Avaya Ip Office Customer Call Reporter