Vulnerability CVE-2022-24630


Published: 2023-05-29

Description:
An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. BrowseFiles.php allows a ?cmd=ssh POST request with an ssh_command field that is executed.

See advisories in our WLB2 database:
Topic
Author
Date
High
Device Manager Express 7.8.20002.47752 SQL Injection / XSS / Code Execution / Traversal
Eric Flokstra
24.02.2023

 References:
http://seclists.org/fulldisclosure/2023/Feb/12

Copyright 2024, cxsecurity.com

 

Back to Top