Vulnerability record · CVE-2012-3811 · published 3 July 2012
CVE-2012-3811: Avaya IP Office Customer Call Reporter unrestricted file upload in ImageUpload.ashx
Avaya · Ip Office Customer Call Reporter
ImageUpload.ashx in the Wallboard component of Avaya IP Office Customer Call Reporter accepts uploaded files without restricting their type, so an attacker can upload an executable and then request it directly. Because the uploaded file is served back and executed, this is effectively remote code execution on the application server. The flaw affects 7.0 before 7.0.5.8 and 8.0 before 8.0.9.13 (Q1 2012 Maintenance Release).
Description
Unrestricted file upload vulnerability in ImageUpload.ashx in the Wallboard application in Avaya IP Office Customer Call Reporter 7.0 before 7.0.5.8 Q1 2012 Maintenance Release and 8.0 before 8.0.9.13 Q1 2012 Maintenance Release allows remote attackers to execute arbitrary code by uploading an executable file and then accessing it via a direct request.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityUnauthenticated network-reachable upload leading to arbitrary code execution with complete impact, and a high EPSS score, make this a top remediation priority despite the lack of KEV listing.
What it is
ImageUpload.ashx in the Wallboard component of Avaya IP Office Customer Call Reporter accepts uploaded files without restricting their type, so an attacker can upload an executable and then request it directly. Because the uploaded file is served back and executed, this is effectively remote code execution on the application server. The flaw affects 7.0 before 7.0.5.8 and 8.0 before 8.0.9.13 (Q1 2012 Maintenance Release).
Impact
An unauthenticated remote attacker can run arbitrary code with the privileges of the web application, leading to full compromise of the server hosting the call reporter. CVSS 2.0 scores it 10.0 with complete confidentiality, integrity and availability impact.
Attack surface
Reachable over the network through the Wallboard ImageUpload.ashx endpoint; the CVSS vector (AV:N/AC:L/Au:N) indicates no authentication and no user interaction are required. The attacker only needs to POST a file and then fetch it by direct URL.
Exploitation
Not listed in CISA KEV and no ransomware association is documented, but EPSS is high at roughly 0.63 (99th percentile), and the Zero Day Initiative advisory reference indicates coordinated public disclosure of the flaw.
What to do
- Upgrade to Avaya IP Office Customer Call Reporter 7.0.5.8 or 8.0.9.13 (Q1 2012 Maintenance Release) or later, per the Avaya vendor advisory.
- If immediate patching is not possible, restrict network access to the Wallboard/ImageUpload.ashx endpoint to trusted management networks only.
- Configure the web server to refuse execution of script or binary content in the upload directory and serve uploaded files as static, non-executable content.
- Validate and whitelist allowed image file types and extensions on upload, and store uploads outside the web root where feasible.
Detection
- Monitor web logs for POST requests to ImageUpload.ashx followed by direct GET requests to the same uploaded file path.
- Alert on files with executable extensions (for example .aspx, .exe, .dll) appearing in the Wallboard upload directory.
- Watch for unexpected child processes spawned by the web application server (w3wp.exe or equivalent) on the call reporter host.
- Review file integrity of the upload directory and flag newly created files that are not valid images.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2012-3811 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Source: NIST National Vulnerability Database (record CVE-2012-3811), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.