3 results (0.002 seconds)

CVSS: 9.8EPSS: 64%CPEs: 3EXPL: 2

An issue was discovered in Pascom Cloud Phone System before 7.20.x. A configuration error between NGINX and a backend Tomcat server leads to a path traversal in the Tomcat server, exposing unintended endpoints. Se ha detectado un problema en Pascom Cloud Phone System versiones anteriores a 7.20.x. Un error de configuración entre NGINX y un servidor Tomcat backend conlleva a un salto de ruta en el servidor Tomcat, exponiendo endpoints no deseados • https://kerbit.io/research/read/blog/4 https://tutorialboy24.blogspot.com/2022/03/the-story-of-3-bugs-that-lead-to.html https://www.pascom.net/doc/en/release-notes https://www.pascom.net/doc/en/release-notes/pascom19 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •

CVSS: 10.0EPSS: 4%CPEs: 1EXPL: 2

An issue was discovered in Pascom Cloud Phone System before 7.20.x. In the management REST API, /services/apply in exd.pl allows remote attackers to execute arbitrary code via shell metacharacters. Se ha detectado un problema en Pascom Cloud Phone System versiones anteriores a 7.20.x. En la API REST de administración, /services/apply en el archivo exd.pl permite a atacantes remotos ejecutar código arbitrario por medio de metacaracteres de shell • https://kerbit.io/research/read/blog/4 https://tutorialboy24.blogspot.com/2022/03/the-story-of-3-bugs-that-lead-to.html https://www.pascom.net/doc/en/release-notes • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •

CVSS: 7.5EPSS: 2%CPEs: 2EXPL: 2

An issue was discovered in xmppserver jar in the XMPP Server component of the JIve platform, as used in Pascom Cloud Phone System before 7.20.x (and in other products). An endpoint in the backend Tomcat server of the Pascom allows SSRF, a related issue to CVE-2019-18394. Se ha detectado un problema en xmppserver jar en el componente XMPP Server de la plataforma JIve, tal como es usado en Pascom Cloud Phone System versiones anteriores a 7.20.x (y en otros productos). Un endpoint en el servidor Tomcat backend de Pascom permite una vulnerabilidad de tipo SSRF, un problema relacionado con CVE-2019-18394 • https://jivesoftware.com/platform https://kerbit.io/research/read/blog/4 https://tutorialboy24.blogspot.com/2022/03/the-story-of-3-bugs-that-lead-to.html https://www.pascom.net/doc/en/release-notes https://www.pascom.net/doc/en/release-notes/pascom19 • CWE-918: Server-Side Request Forgery (SSRF) •