← Back

Alphacom Xe Audio Server

alphacom_xe_audio_server

Vendor: Zenitel • 1 CVE

CVEs (1)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Zenitel
1Alphacom Xe Audio Server
Nov 21, 2024
Sep 15, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
The web part of Zenitel AlphaCom XE Audio Server through 11.2.3.10, called AlphaWeb XE, does not restrict file upload in the Custom Scripts section at php/index.php. Neither the content nor extension of the uploaded file...Show more
The web part of Zenitel AlphaCom XE Audio Server through 11.2.3.10, called AlphaWeb XE, does not restrict file upload in the Custom Scripts section at php/index.php. Neither the content nor extension of the uploaded files is checked, allowing execution of PHP code under the /cmd directory.Show less