Show filters
51 Total Results
Displaying 11-20 of 51
Sort by:
Attacker Value
Unknown
CVE-2020-21057
Disclosure Date: May 20, 2021 (last updated February 22, 2025)
Directory Traversal vulnerability in FusionPBX 4.5.7, which allows a remote malicious user to delete folders on the system via the folder variable to app/edit/folderdelete.php.
0
Attacker Value
Unknown
CVE-2020-21056
Disclosure Date: May 20, 2021 (last updated February 22, 2025)
Directory Traversal vulnerability exists in FusionPBX 4.5.7, which allows a remote malicious user to create folders via the folder variale to app\edit\foldernew.php.
0
Attacker Value
Unknown
CVE-2020-21053
Disclosure Date: May 20, 2021 (last updated February 22, 2025)
Cross Site Scriptiong (XSS) vulnerability exists in FusionPBX 4.5.7 allows remote malicious users to inject arbitrary web script or HTML via an unsanitized "query_string" variable in app\devices\device_imports.php.
0
Attacker Value
Unknown
CVE-2019-19386
Disclosure Date: November 29, 2019 (last updated November 27, 2024)
A cross-site scripting (XSS) vulnerability in app/voicemail_greetings/voicemail_greeting_edit.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary web script or HTML via the id and/or voicemail_id parameter.
0
Attacker Value
Unknown
CVE-2019-19385
Disclosure Date: November 29, 2019 (last updated November 27, 2024)
A cross-site scripting (XSS) vulnerability in app/dialplans/dialplans.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary web script or HTML via the app_uuid parameter.
0
Attacker Value
Unknown
CVE-2019-19384
Disclosure Date: November 29, 2019 (last updated November 27, 2024)
A cross-site scripting (XSS) vulnerability in app/fax/fax_log_view.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary web script or HTML via the fax_uuid parameter.
0
Attacker Value
Unknown
CVE-2019-19388
Disclosure Date: November 29, 2019 (last updated November 27, 2024)
A cross-site scripting (XSS) vulnerability in app/dialplans/dialplan_detail_edit.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary web script or HTML via the dialplan_uuid parameter.
0
Attacker Value
Unknown
CVE-2019-19387
Disclosure Date: November 29, 2019 (last updated November 27, 2024)
A cross-site scripting (XSS) vulnerability in app/fifo_list/fifo_interactive.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary web script or HTML via the c parameter.
0
Attacker Value
Unknown
CVE-2019-19367
Disclosure Date: November 27, 2019 (last updated November 27, 2024)
A cross-site scripting (XSS) vulnerability in app/fax/fax_files.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter.
0
Attacker Value
Unknown
CVE-2019-19366
Disclosure Date: November 27, 2019 (last updated November 27, 2024)
A cross-site scripting (XSS) vulnerability in app/xml_cdr/xml_cdr_search.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary web script or HTML via the redirect parameter.
0