Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
PhoneSystem Terminal in 3CX Phone System (Debian based installation) 16.0.0.1570 allows an authenticated attacker to run arbitrary commands with the phonesystem user privileges because of "<space><space> followed by <shift><enter>" mishandling.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
3CX Phone 命令注入漏洞
Vulnerability Description
3CX Phone是一款基于软件的专用分支交换机。该产品可与基于SIP标准的IP电话、SIP中继和VoIP网关配合使用,提供完整的通信解决方案。 3CX Phone System 16.0.0.1570 版本存在安全漏洞,该漏洞源于部分标签处理不当。经过身份验证的攻击者利用该漏洞可使用电话系统用户权限运行任意命令。
CVSS Information
N/A
Vulnerability Type
N/A