Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Unsanitized input in language form field
Vulnerability Description
In HylaFAX Enterprise Web Interface and AvantFAX, the language form element is not properly sanitized
before being used and can be misused to include an arbitrary file in the
PHP code allowing an attacker to do anything as the web server user.
This flaw requires the attacker to be authenticated with a valid user account.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Vulnerability Type
对生成代码的控制不恰当(代码注入)
Vulnerability Title
iFAX AvantFAX和iFAX HylaFAX Enterprise Web Interface 安全漏洞
Vulnerability Description
iFAX AvantFAX和iFAX HylaFAX Enterprise Web Interface都是iFAX公司的产品。iFAX AvantFAX是一个Web应用程序,允许用户在任何平台上查看和发送传真,而无需安装特殊软件。iFAX HylaFAX Enterprise Web Interface是一个基于 Web 的应用程序,用于管理 HylaFAX 上的传真。 iFAX AvantFAX和iFAX HylaFAX Enterprise Web Interface存在安全漏洞,该漏洞源于语言表单元
CVSS Information
N/A
Vulnerability Type
N/A