Show filters
12 Total Results
Displaying 1-10 of 12
Sort by:
Attacker Value
Moderate

CVE-2020-7351

Disclosure Date: April 28, 2020 (last updated February 21, 2025)
An OS Command Injection vulnerability in the endpoint_devicemap.php component of Fonality Trixbox Community Edition allows an attacker to execute commands on the underlying operating system as the "asterisk" user. Note that Trixbox Community Edition has been unsupported by the vendor since 2012. This issue affects: Fonality Trixbox Community Edition, versions 1.2.0 through 2.8.0.4. Versions 1.0 and 1.1 are unaffected.
Attacker Value
Unknown

CVE-2017-14536

Disclosure Date: February 16, 2018 (last updated November 26, 2024)
trixbox 2.8.0.4 has XSS via the PATH_INFO to /maint/index.php or /user/includes/language/langChooser.php.
0
Attacker Value
Unknown

CVE-2017-14537

Disclosure Date: February 16, 2018 (last updated November 26, 2024)
trixbox 2.8.0.4 has path traversal via the xajaxargs array parameter to /maint/index.php?packages or the lang parameter to /maint/modules/home/index.php.
Attacker Value
Unknown

CVE-2017-14535

Disclosure Date: February 16, 2018 (last updated November 26, 2024)
trixbox 2.8.0.4 has OS command injection via shell metacharacters in the lang parameter to /maint/modules/home/index.php.
Attacker Value
Unknown

CVE-2014-5109

Disclosure Date: July 28, 2014 (last updated October 05, 2023)
SQL injection vulnerability in maint/modules/endpointcfg/endpoint_generic.php in Fonality trixbox allows remote attackers to execute arbitrary SQL commands via the mac parameter in a Submit action.
0
Attacker Value
Unknown

CVE-2014-5111

Disclosure Date: July 28, 2014 (last updated October 05, 2023)
Multiple directory traversal vulnerabilities in Fonality trixbox allow remote attackers to read arbitrary files via a .. (dot dot) in the lang parameter to (1) home/index.php, (2) asterisk_info/asterisk_info.php, (3) repo/repo.php, or (4) endpointcfg/endpointcfg.php in maint/modules/.
0
Attacker Value
Unknown

CVE-2014-5112

Disclosure Date: July 28, 2014 (last updated October 05, 2023)
maint/modules/home/index.php in Fonality trixbox allows remote attackers to execute arbitrary commands via shell metacharacters in the lang parameter.
0
Attacker Value
Unknown

CVE-2014-5110

Disclosure Date: July 28, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in user/help/html/index.php in Fonality trixbox allows remote attackers to inject arbitrary web script or HTML via the id_nodo parameter.
0
Attacker Value
Unknown

CVE-2010-0702

Disclosure Date: February 23, 2010 (last updated October 04, 2023)
SQL injection vulnerability in cisco/services/PhonecDirectory.php in Fonality Trixbox 2.2.4 allows remote attackers to execute arbitrary SQL commands via the ID parameter.
0
Attacker Value
Unknown

CVE-2008-6825

Disclosure Date: June 05, 2009 (last updated October 04, 2023)
Directory traversal vulnerability in user/index.php in Fonality trixbox CE 2.6.1 and earlier allows remote attackers to include and execute arbitrary files via a .. (dot dot) in the langChoice parameter.
0