The CSV upload feature in /supervisor/procesa_carga.php on Logaritmo Aware CallManager 2012 devices allows upload of .php files with a text/* content type. The PHP code can then be executed by visiting a /supervisor/csv/ URI.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2020-01-21T00:37:02

Updated: 2024-08-05T02:39:09.287Z

Reserved: 2020-01-21T00:00:00

Link: CVE-2019-20385

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2020-01-21T01:15:10.867

Modified: 2020-01-29T14:46:05.007

Link: CVE-2019-20385

cve-icon Redhat

No data.