Show filters
10 Total Results
Displaying 1-10 of 10
Sort by:
Attacker Value
Moderate
CVE-2020-7351
Disclosure Date: April 28, 2020 (last updated February 21, 2025)
An OS Command Injection vulnerability in the endpoint_devicemap.php component of Fonality Trixbox Community Edition allows an attacker to execute commands on the underlying operating system as the "asterisk" user. Note that Trixbox Community Edition has been unsupported by the vendor since 2012. This issue affects: Fonality Trixbox Community Edition, versions 1.2.0 through 2.8.0.4. Versions 1.0 and 1.1 are unaffected.
1
Attacker Value
Unknown
CVE-2017-14536
Disclosure Date: February 16, 2018 (last updated November 26, 2024)
trixbox 2.8.0.4 has XSS via the PATH_INFO to /maint/index.php or /user/includes/language/langChooser.php.
0
Attacker Value
Unknown
CVE-2017-14537
Disclosure Date: February 16, 2018 (last updated November 26, 2024)
trixbox 2.8.0.4 has path traversal via the xajaxargs array parameter to /maint/index.php?packages or the lang parameter to /maint/modules/home/index.php.
0
Attacker Value
Unknown
CVE-2017-14535
Disclosure Date: February 16, 2018 (last updated November 26, 2024)
trixbox 2.8.0.4 has OS command injection via shell metacharacters in the lang parameter to /maint/modules/home/index.php.
0
Attacker Value
Unknown
CVE-2014-5109
Disclosure Date: July 28, 2014 (last updated October 05, 2023)
SQL injection vulnerability in maint/modules/endpointcfg/endpoint_generic.php in Fonality trixbox allows remote attackers to execute arbitrary SQL commands via the mac parameter in a Submit action.
0
Attacker Value
Unknown
CVE-2014-5111
Disclosure Date: July 28, 2014 (last updated October 05, 2023)
Multiple directory traversal vulnerabilities in Fonality trixbox allow remote attackers to read arbitrary files via a .. (dot dot) in the lang parameter to (1) home/index.php, (2) asterisk_info/asterisk_info.php, (3) repo/repo.php, or (4) endpointcfg/endpointcfg.php in maint/modules/.
0
Attacker Value
Unknown
CVE-2014-5112
Disclosure Date: July 28, 2014 (last updated October 05, 2023)
maint/modules/home/index.php in Fonality trixbox allows remote attackers to execute arbitrary commands via shell metacharacters in the lang parameter.
0
Attacker Value
Unknown
CVE-2014-5110
Disclosure Date: July 28, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in user/help/html/index.php in Fonality trixbox allows remote attackers to inject arbitrary web script or HTML via the id_nodo parameter.
0
Attacker Value
Unknown
CVE-2010-0702
Disclosure Date: February 23, 2010 (last updated October 04, 2023)
SQL injection vulnerability in cisco/services/PhonecDirectory.php in Fonality Trixbox 2.2.4 allows remote attackers to execute arbitrary SQL commands via the ID parameter.
0
Attacker Value
Unknown
CVE-2007-6424
Disclosure Date: December 18, 2007 (last updated October 04, 2023)
registry.pl in Fonality Trixbox 2.0 PBX products, when running in certain environments, reads and executes a set of commands from a remote web site without sufficiently validating the origin of the commands, which allows remote attackers to disable trixbox and execute arbitrary commands via a DNS spoofing attack.
0