CVE-2012-3811
Avaya IP Office Customer Call Reporter ImageUpload Remote Code Execution Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Unrestricted file upload vulnerability in ImageUpload.ashx in the Wallboard application in Avaya IP Office Customer Call Reporter 7.0 before 7.0.5.8 Q1 2012 Maintenance Release and 8.0 before 8.0.9.13 Q1 2012 Maintenance Release allows remote attackers to execute arbitrary code by uploading an executable file and then accessing it via a direct request.
Vulnerabilidad de subida de fichero no restringido en ImageUpload.ashx en la aplicación Wallboard en Avaya IP Office Customer Call Reporter v7.0 anteriores a v7.0.5.8 Q1 2012 Maintenance Release y v8.0 anteriores a v8.0.9.13 Q1 2012 Maintenance Release, permite a atacantes remotos ejecutar código subiendo un fichero ejecutable y accediendo a él a través de una petición directa.
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Avaya IP Office Customer Call Reporter. Authentication is not required to exploit this vulnerability.
The specific flaw exists because Avaya IP Office Customer Call Reporter allows unauthenticated users to upload files to the webserver through ImageUpload.ashx. The uploaded files will not be stripped of their file extensions and the directory where they are uploaded to has no scripting restrictions. This flaw can lead the remote code execution under the context of the user running the IP Office Customer Call Reporter, usually NETWORK SERVICE.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2012-06-27 CVE Reserved
- 2012-06-28 CVE Published
- 2012-10-10 First Exploit
- 2024-09-16 CVE Updated
- 2024-11-09 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
http://zerodayinitiative.com/advisories/ZDI-12-106 | X_refsource_misc |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/21847 | 2012-10-10 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://downloads.avaya.com/css/P8/documents/100164021 | 2012-07-17 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Avaya Search vendor "Avaya" | Ip Office Customer Call Reporter Search vendor "Avaya" for product "Ip Office Customer Call Reporter" | 7.0 Search vendor "Avaya" for product "Ip Office Customer Call Reporter" and version "7.0" | - |
Affected
| ||||||
Avaya Search vendor "Avaya" | Ip Office Customer Call Reporter Search vendor "Avaya" for product "Ip Office Customer Call Reporter" | 8.0 Search vendor "Avaya" for product "Ip Office Customer Call Reporter" and version "8.0" | - |
Affected
|