DigitalCanion 发现备份恢复功能中存在一个漏洞,允许具有配置备份仓库访问权限的攻击者在恢复过程中向系统植入任意文件。 该缺陷具体存在于备份恢复机制中,该机制未能正确验证还原的 TGZ 归档文件中包含的路径、文件类型、完整性和真实性。应用程序在解压归档文件之前未执行文件签名验证,从而允许特别构造的备份文件包含攻击者可控的文件。 因此,拥有备份 SFTP 或其他配置仓库访问权限的攻击者可以提供一个恶意的 TGZ 归档文件,当系统恢复该文件时,可能会在底层 Linux 系统中放置任意文件。根据提取文件的位置和
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Mitel | Mitel MiVoice Office 400 | 11.0.96.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-104706 | 8.4 HIGH | Mitel MiVoice Office 400 view system files path traversal |
| CVE-2026-104810 | 8.4 HIGH | Mitel MiVoice Office 400 File Management File Browser path traversal vulnerability |
| CVE-2026-104809 | 8.4 HIGH | Mitel MiVoice Office 400 Shared Object Hijacking Leading to Arbitrary Code Execution |
| CVE-2026-104811 | 8.4 HIGH | Mitel MiVoice Office 400 Music on Hold WAV File Upload Code Execution |
| CVE-2026-104806 | 5.5 MEDIUM | Mitel MiVoice Office 400 System Logs Path Traversal Information Disclosure |
| CVE-2026-104807 | 1.9 LOW | Mitel MiVoice Office 400 stored Cross-Site Scripting |
| CVE-2026-104808 | 1.9 LOW | Mitel MiVoice Office 400 stored Cross-Site Scripting |
No comments yet