Show filters
12 Total Results
Displaying 1-10 of 12
Sort by:
Attacker Value
Unknown
CVE-2022-34878
Disclosure Date: June 30, 2022 (last updated February 24, 2025)
SQL Injection vulnerability in User Stats interface (/vicidial/user_stats.php) of VICIdial via the file_download parameter allows attacker to spoof identity, tamper with existing data, allow the complete disclosure of all data on the system, destroy the data or make it otherwise unavailable, and become administrators of the database server.
1
Attacker Value
Unknown
CVE-2024-8504
Disclosure Date: September 10, 2024 (last updated February 26, 2025)
An attacker with authenticated access to VICIdial as an "agent" can execute arbitrary shell commands as the "root" user. This attack can be chained with CVE-2024-8503 to execute arbitrary shell commands starting from an unauthenticated perspective.
0
Attacker Value
Unknown
CVE-2024-8503
Disclosure Date: September 10, 2024 (last updated February 26, 2025)
An unauthenticated attacker can leverage a time-based SQL injection vulnerability in VICIdial to enumerate database records. By default, VICIdial stores plaintext credentials within the database.
0
Attacker Value
Unknown
CVE-2021-35377
Disclosure Date: March 06, 2023 (last updated February 24, 2025)
Cross Site Scripting vulnerability found in VICIdial v2.14-610c and v.2.10-415c allows attackers execute arbitrary code via the /agc/vicidial.php, agc/vicidial-greay.php, and /vicidial/KHOMP_admin.php parameters.
0
Attacker Value
Unknown
CVE-2022-34877
Disclosure Date: June 30, 2022 (last updated February 24, 2025)
SQL Injection vulnerability in AST Agent Time Sheet interface ((/vicidial/AST_agent_time_sheet.php) of VICIdial via the agent parameter allows attacker to spoof identity, tamper with existing data, allow the complete disclosure of all data on the system, destroy the data or make it otherwise unavailable, and become administrators of the database server. This issue affects: VICIdial 2.14b0.5 versions prior to 3555.
0
Attacker Value
Unknown
CVE-2022-34876
Disclosure Date: June 30, 2022 (last updated February 24, 2025)
SQL Injection vulnerability in admin interface (/vicidial/admin.php) of VICIdial via modify_email_accounts, access_recordings, and agentcall_email parameters allows attacker to spoof identity, tamper with existing data, allow the complete disclosure of all data on the system, destroy the data or make it otherwise unavailable, and become administrators of the database server. This issue affects: VICIdial 2.14b0.5 versions prior to 3555.
0
Attacker Value
Unknown
CVE-2022-34879
Disclosure Date: June 30, 2022 (last updated February 24, 2025)
Reflected Cross Site Scripting (XSS) vulnerabilities in AST Agent Time Sheet interface (/vicidial/AST_agent_time_sheet.php) of VICIdial via agent, and search_archived_data parameters. This issue affects: VICIdial 2.14b0.5 versions prior to 3555.
0
Attacker Value
Unknown
CVE-2021-46557
Disclosure Date: February 15, 2022 (last updated February 23, 2025)
Vicidial 2.14-783a was discovered to contain a cross-site scripting (XSS) vulnerability via the input tabs.
0
Attacker Value
Unknown
CVE-2013-7382
Disclosure Date: May 17, 2014 (last updated October 05, 2023)
VICIDIAL dialer (aka Asterisk GUI client) 2.8-403a, 2.7, 2.7RC1, and earlier has a hardcoded password of donotedit for the (1) VDAD and (2) VDCL users, which makes it easier for remote attackers to obtain access.
0
Attacker Value
Unknown
CVE-2013-4468
Disclosure Date: May 14, 2014 (last updated October 05, 2023)
VICIDIAL dialer (aka Asterisk GUI client) 2.8-403a, 2.7, 2.7RC1, and earlier allows remote authenticated users to execute arbitrary commands via shell metacharacters in the extension parameter in an OriginateVDRelogin action to manager_send.php.
0