Privilege Escalation via Incorrect Permission Assignment in Dialogic PowerMedia XMS

Privilege Escalation via Incorrect Permission Assignment in Dialogic PowerMedia XMS

CVE-2018-11642 · HIGH Severity

AV:L/AC:L/AU:N/C:C/I:C/A:C

Incorrect Permission Assignment on the /var/www/xms/cleanzip.sh shell script run periodically in Dialogic PowerMedia XMS through 3.5 allows local users to execute code as the root user.

Learn more about our User Device Pen Test.