peter bassill · operator
$ cve CVE-2012-3811 JSON

CVE-2012-3811 EXPLOIT

10.0
HIGH · CVSS 2.0 · EPSS 62.9% (pctl 99)

Patch early

A public exploit exists.

Description

Unrestricted file upload vulnerability in ImageUpload.ashx in the Wallboard application in Avaya IP Office Customer Call Reporter 7.0 before 7.0.5.8 Q1 2012 Maintenance Release and 8.0 before 8.0.9.13 Q1 2012 Maintenance Release allows remote attackers to execute arbitrary code by uploading an executable file and then accessing it via a direct request.

Scoring

CVSS10.0 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS62.88% — more likely to be exploited than 99% of all CVEs
On CISA KEVno
Public exploityes
Published2012-07-03
Last modified2026-06-16

Affected (1)

VendorProduct
avayaip office customer call reporter

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD