The web part of Zenitel AlphaCom XE Audio Server through 11.2.3.10, called AlphaWeb XE, does not restrict file upload in the Custom Scripts section at php/index.php. Neither the content nor extension of the uploaded files is checked, allowing execution of PHP code under the /cmd directory.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T02:51:07.469Z
Reserved: 2021-09-10T00:00:00
Link: CVE-2021-40845
No data.
Status : Modified
Published: 2021-09-15T13:15:08.410
Modified: 2024-11-21T06:24:54.590
Link: CVE-2021-40845
No data.
OpenCVE Enrichment
No data.
Weaknesses