CVE-2019-16967
- EPSS 0.4%
- Veröffentlicht 21.10.2019 20:15:10
- Zuletzt bearbeitet 21.11.2024 04:31:26
An issue was discovered in Manager 13.x before 13.0.2.6 and 15.x before 15.0.6 before FreePBX 14.0.10.3. In the Manager module form (html\admin\modules\manager\views\form.php), an unsanitized managerdisplay variable coming from the URL is reflected i...
CVE-2019-16966
- EPSS 0.4%
- Veröffentlicht 21.10.2019 19:15:11
- Zuletzt bearbeitet 21.11.2024 04:31:26
An issue was discovered in Contactmanager 13.x before 13.0.45.3, 14.x before 14.0.5.12, and 15.x before 15.0.8.21 for FreePBX 14.0.10.3. In the Contactmanager class (html\admin\modules\contactmanager\Contactmanager.class.php), an unsanitized group va...
CVE-2018-15891
- EPSS 0.35%
- Veröffentlicht 20.06.2019 17:15:09
- Zuletzt bearbeitet 21.11.2024 03:51:39
An issue was discovered in FreePBX core before 3.0.122.43, 14.0.18.34, and 5.0.1beta4. By crafting a request for adding Asterisk modules, an attacker is able to store JavaScript commands in a module name.
CVE-2018-6393
- EPSS 2.35%
- Veröffentlicht 29.01.2018 20:29:00
- Zuletzt bearbeitet 21.11.2024 04:10:37
FreePBX 10.13.66-32bit and 14.0.1.24 (SNG7-PBX-64bit-1712-2) allow post-authentication SQL injection via the order parameter. NOTE: the vendor disputes this issue because it is intentional that a user can "directly modify SQL tables ... [or] run shel...
- EPSS 57.42%
- Veröffentlicht 07.10.2014 14:55:09
- Zuletzt bearbeitet 12.04.2025 10:46:40
htdocs_ari/includes/login.php in the ARI Framework module/Asterisk Recording Interface (ARI) in FreePBX before 2.9.0.9, 2.10.x, and 2.11 before 2.11.1.5 allows remote attackers to execute arbitrary code via the ari_auth cookie, related to the PHP uns...
CVE-2014-1903
- EPSS 84.5%
- Veröffentlicht 18.02.2014 11:55:16
- Zuletzt bearbeitet 11.04.2025 00:51:21
admin/libraries/view.functions.php in FreePBX 2.9 before 2.9.0.14, 2.10 before 2.10.1.15, 2.11 before 2.11.0.23, and 12 before 12.0.1alpha22 does not restrict the set of functions accessible to the API handler, which allows remote attackers to execut...
CVE-2012-4870
- EPSS 7.98%
- Veröffentlicht 06.09.2012 17:55:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
Multiple cross-site scripting (XSS) vulnerabilities in FreePBX 2.9 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) context parameter to panel/index_amp.php or (2) panel/dhtml/index.php; (3) clid or (4) clidname p...
CVE-2012-4869
- EPSS 84.87%
- Veröffentlicht 06.09.2012 17:55:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
The callme_startcall function in recordings/misc/callme_page.php in FreePBX 2.9, 2.10, and earlier allows remote attackers to execute arbitrary commands via the callmenum parameter in a c action.
CVE-2010-3490
- EPSS 8.97%
- Veröffentlicht 28.09.2010 18:00:03
- Zuletzt bearbeitet 11.04.2025 00:51:21
Directory traversal vulnerability in page.recordings.php in the System Recordings component in the configuration interface in FreePBX 2.8.0 and earlier allows remote authenticated administrators to create arbitrary files via a .. (dot dot) in the use...
CVE-2009-1801
- EPSS 0.48%
- Veröffentlicht 28.05.2009 14:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple cross-site scripting (XSS) vulnerabilities in FreePBX 2.5.1, and other 2.4.x, 2.5.x, and pre-release 2.6.x versions, allow remote attackers to inject arbitrary web script or HTML via the (1) display parameter to reports.php, the (2) order an...