Show filters
51 Total Results
Displaying 31-40 of 51
Sort by:
Attacker Value
Unknown

CVE-2019-16964

Disclosure Date: October 21, 2019 (last updated November 27, 2024)
app/call_centers/cmd.php in the Call Center Queue Module in FusionPBX up to 4.5.7 suffers from a command injection vulnerability due to a lack of input validation, which allows authenticated attackers (with at least the permission call_center_queue_add or call_center_queue_edit) to execute any commands on the host as www-data.
Attacker Value
Unknown

CVE-2019-16965

Disclosure Date: October 21, 2019 (last updated November 27, 2024)
resources/cmd.php in FusionPBX up to 4.5.7 suffers from a command injection vulnerability due to a lack of input validation, which allows authenticated administrative attackers to execute any commands on the host as www-data.
Attacker Value
Unknown

CVE-2019-16985

Disclosure Date: October 21, 2019 (last updated November 27, 2024)
In FusionPBX up to v4.5.7, the file app\xml_cdr\xml_cdr_delete.php uses an unsanitized "rec" variable coming from the URL, which is base64 decoded and allows deletion of any file of the system.
Attacker Value
Unknown

CVE-2019-16988

Disclosure Date: October 21, 2019 (last updated November 27, 2024)
In FusionPBX up to v4.5.7, the file app\basic_operator_panel\resources\content.php uses an unsanitized "eavesdrop_dest" variable coming from the URL, which is reflected on 3 occasions in HTML, leading to XSS.
Attacker Value
Unknown

CVE-2019-16981

Disclosure Date: October 21, 2019 (last updated November 27, 2024)
In FusionPBX up to v4.5.7, the file app\conference_profiles\conference_profile_params.php uses an unsanitized "id" variable coming from the URL, which is reflected on 2 occasions in HTML, leading to XSS.
Attacker Value
Unknown

CVE-2019-16987

Disclosure Date: October 21, 2019 (last updated November 27, 2024)
In FusionPBX up to v4.5.7, the file app\contacts\contact_import.php uses an unsanitized "query_string" variable coming from the URL, which is reflected in HTML, leading to XSS.
Attacker Value
Unknown

CVE-2019-16982

Disclosure Date: October 21, 2019 (last updated November 27, 2024)
In FusionPBX up to v4.5.7, the file app\access_controls\access_control_nodes.php uses an unsanitized "id" variable coming from the URL, which is reflected in HTML, leading to XSS.
Attacker Value
Unknown

CVE-2019-16991

Disclosure Date: October 21, 2019 (last updated November 27, 2024)
In FusionPBX up to v4.5.7, the file app\edit\filedelete.php uses an unsanitized "file" variable coming from the URL, which is reflected in HTML, leading to XSS.
Attacker Value
Unknown

CVE-2019-16983

Disclosure Date: October 21, 2019 (last updated November 27, 2024)
In FusionPBX up to v4.5.7, the file resources\paging.php has a paging function (called by several pages of the interface), which uses an unsanitized "param" variable constructed partially from the URL args and reflected in HTML, leading to XSS.
Attacker Value
Unknown

CVE-2019-16989

Disclosure Date: October 21, 2019 (last updated November 27, 2024)
In FusionPBX up to v4.5.7, the file app\conferences_active\conference_interactive.php uses an unsanitized "c" variable coming from the URL, which is reflected in HTML, leading to XSS.