Beveiligingsadvies

CVE-2013-5757

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2014-08-03 18:00:00
Laatst bijgewerkt 2024-08-06 17:22:30
Toegewezen door mitre
CVSS-score geen score
Status PUBLISHED

Beschrijving

Absolute path traversal vulnerability in Yealink VoIP Phone SIP-T38G allows remote authenticated users to read arbitrary files via a full pathname in the dumpConfigFile function in the command parameter to cgi-bin/cgiServer.exx.