RULE(RULE ID:338311)

Rule General Information
Release Date: 2024-08-13
Rule Name: SPON-IP Network Intercom Broadcasting System addmediadata.php Arbitrary File Upload Vulnerability
Severity:
CVE ID:
Rule Protection Details
Description: The SPON-IP network intercom broadcasting system of Shibang Communication is a pure digital transmission bidirectional audio amplification system using XCoIP technology. It transmits audio signals in the form of data packets through local area networks and wide area networks, and has the characteristics of excellent sound quality, infinite transmission distance extension, and easy device use. It is widely used in multiple fields such as education, finance, justice, and transportation. Its addmediadata.php file has an arbitrary file upload vulnerability, which allows attackers to upload malicious files and execute malicious programs on the server.
Impact: Attackers can upload viruses, Trojans, WebShell, other malicious scripts or pictures containing scripts to the server, and attackers can use these files for subsequent attacks.
Affected OS: Windows, Linux, Others
Reference:
Solutions
Please contact the software vendor to update the software patch.