EIP-2026-103166
PRE-CVEMitel Audio and Web Conferencing (AWC) - Arbitrary Shell Command Injection
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-103166. PoCs published by Jan Fry.
AI-analyzed exploit summary This exploit demonstrates a command injection vulnerability in Mitel Audio and Web Conferencing (AWC) by injecting shell commands via the 'xsl' parameter in a URL. The vulnerability allows remote attackers to execute arbitrary commands with the privileges of the application user.
Description
Mitel Audio and Web Conferencing (AWC) - Arbitrary Shell Command Injection
Exploits (1)
This exploit demonstrates a command injection vulnerability in Mitel Audio and Web Conferencing (AWC) by injecting shell commands via the 'xsl' parameter in a URL. The vulnerability allows remote attackers to execute arbitrary commands with the privileges of the application user.