cbcvebase.

Netfortris Trixbox vulnerabilities

6 known vulnerabilities affecting netfortris/trixbox.

Total CVEs
6
CISA KEV
0
Public exploits
4
Exploited in wild
0
Severity breakdown
HIGH3MEDIUM3

Vulnerabilities

Page 1 of 1
CVE-2020-7351P2HIGHCVSS 8.8PoC≥ 1.2.0, ≤ 2.8.0.42020-05-01
CVE-2020-7351 [HIGH] CWE-78 CVE-2020-7351: An OS Command Injection vulnerability in the endpoint_devicemap.php component of Fonality Trixbox Co An OS Command Injection vulnerability in the endpoint_devicemap.php component of Fonality Trixbox Community Edition allows an attacker to execute commands on the underlying operating system as the "asterisk" user. Note that Trixbox Community Edition has been unsupported by the vendor since 2012. This issue affects: Fonality Trixbox Community Edition, ver
nvd
CVE-2017-14535P2HIGHCVSS 8.8PoCv2.8.0.42018-02-16
CVE-2017-14535 [HIGH] CWE-78 CVE-2017-14535: trixbox 2.8.0.4 has OS command injection via shell metacharacters in the lang parameter to /maint/mo trixbox 2.8.0.4 has OS command injection via shell metacharacters in the lang parameter to /maint/modules/home/index.php.
nvd
CVE-2017-14537P3MEDIUMCVSS 6.5PoCv2.8.0.42018-02-16
CVE-2017-14537 [MEDIUM] CWE-22 CVE-2017-14537: trixbox 2.8.0.4 has path traversal via the xajaxargs array parameter to /maint/index.php?packages or trixbox 2.8.0.4 has path traversal via the xajaxargs array parameter to /maint/index.php?packages or the lang parameter to /maint/modules/home/index.php.
nvd
CVE-2010-0702P3HIGHCVSS 7.5PoCv2.2.42010-02-23
CVE-2010-0702 [HIGH] CWE-89 CVE-2010-0702: SQL injection vulnerability in cisco/services/PhonecDirectory.php in Fonality Trixbox 2.2.4 allows r SQL injection vulnerability in cisco/services/PhonecDirectory.php in Fonality Trixbox 2.2.4 allows remote attackers to execute arbitrary SQL commands via the ID parameter.
nvd
CVE-2007-6424P4MEDIUMCVSS 4.3v2.02007-12-18
CVE-2007-6424 [MEDIUM] CWE-264 CVE-2007-6424: registry.pl in Fonality Trixbox 2.0 PBX products, when running in certain environments, reads and ex registry.pl in Fonality Trixbox 2.0 PBX products, when running in certain environments, reads and executes a set of commands from a remote web site without sufficiently validating the origin of the commands, which allows remote attackers to disable trixbox and execute arbitrary commands via a DNS spoofing attack.
nvd
CVE-2017-14536P4MEDIUMCVSS 5.4v2.8.0.42018-02-16
CVE-2017-14536 [MEDIUM] CWE-79 CVE-2017-14536: trixbox 2.8.0.4 has XSS via the PATH_INFO to /maint/index.php or /user/includes/language/langChooser trixbox 2.8.0.4 has XSS via the PATH_INFO to /maint/index.php or /user/includes/language/langChooser.php.
nvd
Netfortris Trixbox vulnerabilities | cvebase