sendfax.php in iFAX AvantFAX before 3.3.6 and HylaFAX Enterprise Web Interface before 0.2.5 allows authenticated Command Injection.
References
Link | Resource |
---|---|
ftp://ftp.ifax.com/security/CVE-2020-11766.html | Vendor Advisory |
Information
Published : 2020-05-19 13:15
Updated : 2021-07-21 04:39
NVD link : CVE-2020-11766
Mitre link : CVE-2020-11766
JSON object : View
CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Products Affected
ifax
- hylafax
avantfax
- avantfax