Записи fusionpbx
52 опубликованных записей вендора fusionpbx.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 1 · 1,9 %
- Pre-auth RCE
- 3
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')32
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')6
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')6
- CWE-116 Improper Encoding or Escaping of Output1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
- CWE-20 Improper Input Validation1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
52 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
61На этой неделе | CVE-2019-11409Готовый эксплойт | app/operator_panel/exec.php in the Operator Panel module in FusionPBX 4.4.3 suffers from a command injection vulnerability due to a lack of fusionpbx · fusionpbx · CWE-78 | Высокая8,8 | — | 87,5 % | 17 июн. 2019 г. |
46В плане | CVE-2021-43405Proof of concept | An issue was discovered in FusionPBX before 4.5.30.fusionpbx · fusionpbx | Высокая8,8 | — | 35,6 % | 5 нояб. 2021 г. |
40В плане | CVE-2022-35153Эксплойта нет | FusionPBX 5.0.1 was discovered to contain a command injection vulnerability via /fax/fax_send.php.fusionpbx · fusionpbx · CWE-116 | Критическая9,8 | — | 1,8 % | 18 авг. 2022 г. |
39Наблюдать | CVE-2019-15029Proof of concept | FusionPBX 4.4.8 allows an attacker to execute arbitrary system commands by submitting a malicious command to the service_edit.php file (whicfusionpbx · fusionpbx · CWE-78 | Высокая8,8 | — | 12,3 % | 5 сент. 2019 г. |
39Наблюдать | CVE-2022-28055Эксплойта нет | Fusionpbx v4.4 and below contains a command injection vulnerability via the download email logs function.fusionpbx · fusionpbx · CWE-78 | Критическая9,8 | — | 1,5 % | 3 мая 2022 г. |
36Наблюдать | CVE-2019-16964Эксплойта нет | app/call_centers/cmd.php in the Call Center Queue Module in FusionPBX up to 4.5.7 suffers from a command injection vulnerability due to a lafusionpbx · fusionpbx · CWE-78 | Высокая8,8 | — | 2,0 % | 21 окт. 2019 г. |
35Наблюдать | CVE-2019-16980Эксплойта нет | In FusionPBX up to v4.5.7, the file app\call_broadcast\call_broadcast_edit.php uses an unsanitized "id" variable coming from the URL in an ufusionpbx · fusionpbx · CWE-89 | Высокая8,8 | — | 1,2 % | 21 окт. 2019 г. |
35Наблюдать | CVE-2021-43404Эксплойта нет | An issue was discovered in FusionPBX before 4.5.30.fusionpbx · fusionpbx | Высокая8,8 | — | 1,0 % | 5 нояб. 2021 г. |
35Наблюдать | CVE-2021-43406Эксплойта нет | An issue was discovered in FusionPBX before 4.5.30.fusionpbx · fusionpbx · CWE-20 | Высокая8,8 | — | 1,0 % | 5 нояб. 2021 г. |
32Наблюдать | CVE-2020-21057Эксплойта нет | Directory Traversal vulnerability in FusionPBX 4.5.7, which allows a remote malicious user to delete folders on the system via the folder vafusionpbx · fusionpbx · CWE-22 | Высокая8,1 | — | 1,5 % | 20 мая 2021 г. |
29Наблюдать | CVE-2019-11410Эксплойта нет | app/backup/index.php in the Backup Module in FusionPBX 4.4.3 suffers from a command injection vulnerability due to a lack of input validatiofusionpbx · fusionpbx · CWE-78 | Высокая7,2 | — | 3,4 % | 17 июн. 2019 г. |
29Наблюдать | CVE-2019-16965Эксплойта нет | resources/cmd.php in FusionPBX up to 4.5.7 suffers from a command injection vulnerability due to a lack of input validation, which allows aufusionpbx · fusionpbx · CWE-78 | Высокая7,2 | — | 3,0 % | 21 окт. 2019 г. |
28Наблюдать | CVE-2019-11407Эксплойта нет | app/operator_panel/index_inc.php in the Operator Panel module in FusionPBX 4.4.3 suffers from an information disclosure vulnerability due tofusionpbx · fusionpbx · CWE-200 | Высокая7,2 | — | 1,5 % | 17 июн. 2019 г. |
26Наблюдать | CVE-2019-11408Proof of concept | XSS in app/operator_panel/index_inc.php in the Operator Panel module in FusionPBX 4.4.3 allows remote unauthenticated attackers to inject arfusionpbx · fusionpbx · CWE-79 | Средняя6,1 | — | 6,9 % | 17 июн. 2019 г. |
26Наблюдать | CVE-2019-16986Эксплойта нет | In FusionPBX up to v4.5.7, the file resources\download.php uses an unsanitized "f" variable coming from the URL, which takes any pathname anfusionpbx · fusionpbx · CWE-22 | Средняя6,5 | — | 1,4 % | 21 окт. 2019 г. |
26Наблюдать | CVE-2019-16990Эксплойта нет | In FusionPBX up to v4.5.7, the file app/music_on_hold/music_on_hold.php uses an unsanitized "file" variable coming from the URL, which takesfusionpbx · fusionpbx · CWE-22 | Средняя6,5 | — | 1,3 % | 21 окт. 2019 г. |
26Наблюдать | CVE-2020-21055Эксплойта нет | A Directory Traversal vulnerability exists in FusionPBX 4.5.7 allows malicoius users to rename any file of the system.via the (1) folder, (2fusionpbx · fusionpbx · CWE-22 | Средняя6,5 | — | 1,2 % | 20 мая 2021 г. |
26Наблюдать | CVE-2019-16985Эксплойта нет | In FusionPBX up to v4.5.7, the file app\xml_cdr\xml_cdr_delete.php uses an unsanitized "rec" variable coming from the URL, which is base64 dfusionpbx · fusionpbx · CWE-22 | Средняя6,5 | — | 1,1 % | 21 окт. 2019 г. |
26Наблюдать | CVE-2021-43403Эксплойта нет | An issue was discovered in FusionPBX before 4.5.30.fusionpbx · fusionpbx | Средняя6,5 | — | 0,9 % | 28 сент. 2022 г. |
24Наблюдать | CVE-2019-19387Эксплойта нет | A cross-site scripting (XSS) vulnerability in app/fifo_list/fifo_interactive.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrfusionpbx · fusionpbx · CWE-79 | Средняя6,1 | — | 0,9 % | 28 нояб. 2019 г. |
24Наблюдать | CVE-2019-19386Эксплойта нет | A cross-site scripting (XSS) vulnerability in app/voicemail_greetings/voicemail_greeting_edit.php in FusionPBX 4.4.1 allows remote attackersfusionpbx · fusionpbx · CWE-79 | Средняя6,1 | — | 0,9 % | 28 нояб. 2019 г. |
24Наблюдать | CVE-2019-19366Эксплойта нет | A cross-site scripting (XSS) vulnerability in app/xml_cdr/xml_cdr_search.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary fusionpbx · fusionpbx · CWE-79 | Средняя6,1 | — | 0,9 % | 27 нояб. 2019 г. |
24Наблюдать | CVE-2019-19367Эксплойта нет | A cross-site scripting (XSS) vulnerability in app/fax/fax_files.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary web scripfusionpbx · fusionpbx · CWE-79 | Средняя6,1 | — | 0,9 % | 27 нояб. 2019 г. |
24Наблюдать | CVE-2019-19384Эксплойта нет | A cross-site scripting (XSS) vulnerability in app/fax/fax_log_view.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary web scfusionpbx · fusionpbx · CWE-79 | Средняя6,1 | — | 0,9 % | 28 нояб. 2019 г. |
24Наблюдать | CVE-2019-19385Эксплойта нет | A cross-site scripting (XSS) vulnerability in app/dialplans/dialplans.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary webfusionpbx · fusionpbx · CWE-79 | Средняя6,1 | — | 0,9 % | 28 нояб. 2019 г. |
- CVE-2019-1140961На этой неделе
app/operator_panel/exec.php in the Operator Panel module in FusionPBX 4.4.3 suffers from a command injection vulnerability due to a lack of
ВысокаяCVSS 8,8Готовый эксплойтEPSS 87 %fusionpbx · fusionpbx17 июн. 2019 г.
- CVE-2021-4340546В плане
An issue was discovered in FusionPBX before 4.5.30.
ВысокаяCVSS 8,8Proof of conceptEPSS 36 %fusionpbx · fusionpbx5 нояб. 2021 г.
- CVE-2022-3515340В плане
FusionPBX 5.0.1 was discovered to contain a command injection vulnerability via /fax/fax_send.php.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %fusionpbx · fusionpbx18 авг. 2022 г.
- CVE-2019-1502939Наблюдать
FusionPBX 4.4.8 allows an attacker to execute arbitrary system commands by submitting a malicious command to the service_edit.php file (whic
ВысокаяCVSS 8,8Proof of conceptEPSS 12 %fusionpbx · fusionpbx5 сент. 2019 г.
- CVE-2022-2805539Наблюдать
Fusionpbx v4.4 and below contains a command injection vulnerability via the download email logs function.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %fusionpbx · fusionpbx3 мая 2022 г.
- CVE-2019-1696436Наблюдать
app/call_centers/cmd.php in the Call Center Queue Module in FusionPBX up to 4.5.7 suffers from a command injection vulnerability due to a la
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %fusionpbx · fusionpbx21 окт. 2019 г.
- CVE-2019-1698035Наблюдать
In FusionPBX up to v4.5.7, the file app\call_broadcast\call_broadcast_edit.php uses an unsanitized "id" variable coming from the URL in an u
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %fusionpbx · fusionpbx21 окт. 2019 г.
- CVE-2021-4340435Наблюдать
An issue was discovered in FusionPBX before 4.5.30.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %fusionpbx · fusionpbx5 нояб. 2021 г.
- CVE-2021-4340635Наблюдать
An issue was discovered in FusionPBX before 4.5.30.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %fusionpbx · fusionpbx5 нояб. 2021 г.
- CVE-2020-2105732Наблюдать
Directory Traversal vulnerability in FusionPBX 4.5.7, which allows a remote malicious user to delete folders on the system via the folder va
ВысокаяCVSS 8,1Эксплойта нетEPSS 2 %fusionpbx · fusionpbx20 мая 2021 г.
- CVE-2019-1141029Наблюдать
app/backup/index.php in the Backup Module in FusionPBX 4.4.3 suffers from a command injection vulnerability due to a lack of input validatio
ВысокаяCVSS 7,2Эксплойта нетEPSS 3 %fusionpbx · fusionpbx17 июн. 2019 г.
- CVE-2019-1696529Наблюдать
resources/cmd.php in FusionPBX up to 4.5.7 suffers from a command injection vulnerability due to a lack of input validation, which allows au
ВысокаяCVSS 7,2Эксплойта нетEPSS 3 %fusionpbx · fusionpbx21 окт. 2019 г.
- CVE-2019-1140728Наблюдать
app/operator_panel/index_inc.php in the Operator Panel module in FusionPBX 4.4.3 suffers from an information disclosure vulnerability due to
ВысокаяCVSS 7,2Эксплойта нетEPSS 2 %fusionpbx · fusionpbx17 июн. 2019 г.
- CVE-2019-1140826Наблюдать
XSS in app/operator_panel/index_inc.php in the Operator Panel module in FusionPBX 4.4.3 allows remote unauthenticated attackers to inject ar
СредняяCVSS 6,1Proof of conceptEPSS 7 %fusionpbx · fusionpbx17 июн. 2019 г.
- CVE-2019-1698626Наблюдать
In FusionPBX up to v4.5.7, the file resources\download.php uses an unsanitized "f" variable coming from the URL, which takes any pathname an
СредняяCVSS 6,5Эксплойта нетEPSS 1 %fusionpbx · fusionpbx21 окт. 2019 г.
- CVE-2019-1699026Наблюдать
In FusionPBX up to v4.5.7, the file app/music_on_hold/music_on_hold.php uses an unsanitized "file" variable coming from the URL, which takes
СредняяCVSS 6,5Эксплойта нетEPSS 1 %fusionpbx · fusionpbx21 окт. 2019 г.
- CVE-2020-2105526Наблюдать
A Directory Traversal vulnerability exists in FusionPBX 4.5.7 allows malicoius users to rename any file of the system.via the (1) folder, (2
СредняяCVSS 6,5Эксплойта нетEPSS 1 %fusionpbx · fusionpbx20 мая 2021 г.
- CVE-2019-1698526Наблюдать
In FusionPBX up to v4.5.7, the file app\xml_cdr\xml_cdr_delete.php uses an unsanitized "rec" variable coming from the URL, which is base64 d
СредняяCVSS 6,5Эксплойта нетEPSS 1 %fusionpbx · fusionpbx21 окт. 2019 г.
- CVE-2021-4340326Наблюдать
An issue was discovered in FusionPBX before 4.5.30.
СредняяCVSS 6,5Эксплойта нетEPSS 1 %fusionpbx · fusionpbx28 сент. 2022 г.
- CVE-2019-1938724Наблюдать
A cross-site scripting (XSS) vulnerability in app/fifo_list/fifo_interactive.php in FusionPBX 4.4.1 allows remote attackers to inject arbitr
СредняяCVSS 6,1Эксплойта нетEPSS 1 %fusionpbx · fusionpbx28 нояб. 2019 г.
- CVE-2019-1938624Наблюдать
A cross-site scripting (XSS) vulnerability in app/voicemail_greetings/voicemail_greeting_edit.php in FusionPBX 4.4.1 allows remote attackers
СредняяCVSS 6,1Эксплойта нетEPSS 1 %fusionpbx · fusionpbx28 нояб. 2019 г.
- CVE-2019-1936624Наблюдать
A cross-site scripting (XSS) vulnerability in app/xml_cdr/xml_cdr_search.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary
СредняяCVSS 6,1Эксплойта нетEPSS 1 %fusionpbx · fusionpbx27 нояб. 2019 г.
- CVE-2019-1936724Наблюдать
A cross-site scripting (XSS) vulnerability in app/fax/fax_files.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary web scrip
СредняяCVSS 6,1Эксплойта нетEPSS 1 %fusionpbx · fusionpbx27 нояб. 2019 г.
- CVE-2019-1938424Наблюдать
A cross-site scripting (XSS) vulnerability in app/fax/fax_log_view.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary web sc
СредняяCVSS 6,1Эксплойта нетEPSS 1 %fusionpbx · fusionpbx28 нояб. 2019 г.
- CVE-2019-1938524Наблюдать
A cross-site scripting (XSS) vulnerability in app/dialplans/dialplans.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary web
СредняяCVSS 6,1Эксплойта нетEPSS 1 %fusionpbx · fusionpbx28 нояб. 2019 г.