Digital Canyon 发现了一个路径遍历漏洞,攻击者可利用该漏洞访问预期目录之外的文件。 具体而言,该缺陷存在于 Web 管理门户中监听 TCP 443 端口的“维护 → 系统日志”功能模块中。应用程序未能正确验证用户提供的文件路径,使得攻击者能够操纵请求路径,从而遍历底层目录结构。 利用此漏洞,攻击者可以访问并下载位于预期系统日志目录之外的文件,包括潜在敏感的系统文件和应用程序文件。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Mitel | Mitel MiVoice Office 400 | 11.0.96.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-104805 | 8.5 HIGH | Mitel MiVoice Office 400 Backup Restoration Arbitrary File Write Leading to Root Code Exec |
| CVE-2026-104706 | 8.4 HIGH | Mitel MiVoice Office 400 view system files path traversal |
| CVE-2026-104810 | 8.4 HIGH | Mitel MiVoice Office 400 File Management File Browser path traversal vulnerability |
| CVE-2026-104809 | 8.4 HIGH | Mitel MiVoice Office 400 Shared Object Hijacking Leading to Arbitrary Code Execution |
| CVE-2026-104811 | 8.4 HIGH | Mitel MiVoice Office 400 Music on Hold WAV File Upload Code Execution |
| CVE-2026-104807 | 1.9 LOW | Mitel MiVoice Office 400 stored Cross-Site Scripting |
| CVE-2026-104808 | 1.9 LOW | Mitel MiVoice Office 400 stored Cross-Site Scripting |
No comments yet