漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Telenia TVox 26.5.3 OS Command Injection via action_audio.php
Vulnerability Description
Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain an OS command injection vulnerability in action_audio.php that allows authenticated attackers to execute arbitrary operating system commands by passing an unsanitized pid parameter into an exec() call when the action parameter is set to checkProcess. Attackers can inject malicious OS commands through the pid request parameter to execute arbitrary commands with the privileges of the apache user.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
OS命令中使用的特殊元素转义处理不恰当(OS命令注入)
Vulnerability Title
Telenia Software TVox 命令注入漏洞
Vulnerability Description
Telenia Software TVox是Telenia Software公司的一款VoIP电话系统软件。 Telenia Software TVox 26.5.3及之前的26.x版本和24.9.21及之前的24.x版本存在命令注入漏洞,该漏洞源于action_audio.php文件对pid参数验证不足,攻击者可设置action参数为checkProcess,将未清理的pid参数传入exec()调用,从而注入恶意操作系统命令,以apache用户权限执行任意命令。
CVSS Information
N/A
Vulnerability Type
N/A