Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

This site is deprecated. Please CLICK HERE for latest updates

Short Name

HTTP:FILE-UPLOAD-3CX-PHONE

Severity

Major

Recommended

Yes

Recommended Action

Drop

Category

HTTP

Keywords

3CX Phone System VAD_Deploy_aspx Arbitrary File Upload

Release Date

2017/01/09

Update Number

2820

Supported Platforms

idp-4.0+, isg-3.0+, j-series-9.5+, mx-11.4+, srx-12.1+, srx-branch-12.1+, vmx-17.4+, vsrx-12.1+, vsrx3bsd-18.2+

HTTP: 3CX Phone System VAD_Deploy_aspx Arbitrary File Upload


An arbitrary file upload vulnerability exists in 3CX VoIP Phone System Manager. The vulnerability is due to failure to restrict file uploads in VAD_Deploy.aspx. A remote unauthenticated attacker can exploit this vulnerability by sending maliciously crafted requests to the target server. Successful exploitation could lead to arbitrary command execution on the server with SYSTEM privileges.

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out