An issue exists in AudioCodes Device Manager Express up to and including 7.8.20002.47752. BrowseFiles.php allows a ?cmd=ssh POST request with an ssh_command field that is executed.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
audiocodes device manager express |