FreePBX kayıtları
freepbx üreticisine ait 14 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 1 · %7,1
- Pre-auth RCE
- 2
- Düzeltme kaydı olan
- %7,1
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')5
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
14 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
53Planlayın | CVE-2014-7235Kavram kanıtı | htdocs_ari/includes/login.php in the ARI Framework module/Asterisk Recording Interface (ARI) in FreePBX before 2.9.0.9, 2.10.x, and 2.11 beffreepbx · freepbx · CWE-94 | Kritik10,0 | — | %43,3 | 7 Eki 2014 |
46Planlayın | CVE-2014-1903Silahlaştırılmış | admin/libraries/view.functions.php in FreePBX 2.9 before 2.9.0.14, 2.10 before 2.10.1.15, 2.11 before 2.11.0.23, and 12 before 12.0.1alpha22freepbx · freepbx · CWE-264 | Yüksek7,5 | — | %52,8 | 18 Şub 2014 |
35İzleyin | CVE-2026-40520İstismar yok | FreePBX api module Command Injection via GraphQLfreepbx · api · CWE-78 | Yüksek8,6 | — | %2,4 | 21 Nis 2026 |
28İzleyin | CVE-2007-2191Kavram kanıtı | Multiple cross-site scripting (XSS) vulnerabilities in freePBX 2.2.x allow remote attackers to inject arbitrary web script or HTML via the (freepbx · freepbx | Orta6,8 | — | %4,5 | 24 Nis 2007 |
27İzleyin | CVE-2007-2350İstismar yok | admin/config.php in the music-on-hold module in freePBX 2.2.x allows remote authenticated administrators to execute arbitrary commands via sfreepbx · freepbx | Orta6,5 | — | %2,3 | 30 Nis 2007 |
27İzleyin | CVE-2009-1802İstismar yok | Multiple cross-site request forgery (CSRF) vulnerabilities in FreePBX 2.5.1, and other 2.4.x, 2.5.x, and pre-release 2.6.x versions, allow rfreepbx · freepbx · CWE-352 | Orta6,8 | — | %0,6 | 28 May 2009 |
27İzleyin | CVE-2024-47071İstismar yok | OSS Endpoint Manager allows unauthorized access to read system filesfreepbx · endpointman · CWE-22 | Orta6,8 | — | %0,5 | 1 Eki 2024 |
24İzleyin | CVE-2019-16967İstismar yok | An issue was discovered in Manager 13.x before 13.0.2.6 and 15.x before 15.0.6 before FreePBX 14.0.10.3.freepbx · manager · CWE-79 | Orta6,1 | — | %1,3 | 21 Eki 2019 |
24İzleyin | CVE-2019-16966İstismar yok | An issue was discovered in Contactmanager 13.x before 13.0.45.3, 14.x before 14.0.5.12, and 15.x before 15.0.8.21 for FreePBX 14.0.10.3.freepbx · contactmanager · CWE-79 | Orta6,1 | — | %1,1 | 21 Eki 2019 |
20İzleyin | CVE-2009-1803İstismar yok | FreePBX 2.5.1, and other 2.4.x, 2.5.x, and pre-release 2.6.x versions, generates different error messages for a failed login attempt dependifreepbx · freepbx · CWE-200 | Orta5,0 | — | %1,2 | 28 May 2009 |
19İzleyin | CVE-2018-15891İstismar yok | An issue was discovered in FreePBX core before 3.0.122.43, 14.0.18.34, and 5.0.1beta4.freepbx · freepbx · CWE-79 | Orta4,8 | — | %0,6 | 20 Haz 2019 |
18İzleyin | CVE-2009-4458Kavram kanıtı | Multiple cross-site scripting (XSS) vulnerabilities in FreePBX 2.5.2 and 2.6.0rc2, and possibly other versions, allow remote attackers to infreepbx · freepbx · CWE-79 | Orta4,3 | — | %1,8 | 29 Ara 2009 |
17İzleyin | CVE-2009-1801İstismar yok | Multiple cross-site scripting (XSS) vulnerabilities in FreePBX 2.5.1, and other 2.4.x, 2.5.x, and pre-release 2.6.x versions, allow remote afreepbx · freepbx · CWE-79 | Orta4,3 | — | %1,3 | 28 May 2009 |
17İzleyin | CVE-2018-15892İstismar yok | FreePBX 13 and 14 has SQL Injection in the DISA module via the hangup variable on the /admin/config.php?display=disa&view=form page.freepbx · disa · CWE-89 | Orta4,3 | — | %0,5 | 20 Haz 2019 |
- CVE-2014-723553Planlayın
htdocs_ari/includes/login.php in the ARI Framework module/Asterisk Recording Interface (ARI) in FreePBX before 2.9.0.9, 2.10.x, and 2.11 bef
KritikCVSS 10,0Kavram kanıtıEPSS %43freepbx · freepbx7 Eki 2014
- CVE-2014-190346Planlayın
admin/libraries/view.functions.php in FreePBX 2.9 before 2.9.0.14, 2.10 before 2.10.1.15, 2.11 before 2.11.0.23, and 12 before 12.0.1alpha22
YüksekCVSS 7,5SilahlaştırılmışEPSS %53freepbx · freepbx18 Şub 2014
- CVE-2026-4052035İzleyin
FreePBX api module Command Injection via GraphQL
YüksekCVSS 8,6İstismar yokEPSS %2freepbx · api21 Nis 2026
- CVE-2007-219128İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in freePBX 2.2.x allow remote attackers to inject arbitrary web script or HTML via the (
OrtaCVSS 6,8Kavram kanıtıEPSS %4freepbx · freepbx24 Nis 2007
- CVE-2007-235027İzleyin
admin/config.php in the music-on-hold module in freePBX 2.2.x allows remote authenticated administrators to execute arbitrary commands via s
OrtaCVSS 6,5İstismar yokEPSS %2freepbx · freepbx30 Nis 2007
- CVE-2009-180227İzleyin
Multiple cross-site request forgery (CSRF) vulnerabilities in FreePBX 2.5.1, and other 2.4.x, 2.5.x, and pre-release 2.6.x versions, allow r
OrtaCVSS 6,8İstismar yokEPSS %1freepbx · freepbx28 May 2009
- CVE-2024-4707127İzleyin
OSS Endpoint Manager allows unauthorized access to read system files
OrtaCVSS 6,8İstismar yokEPSS %1freepbx · endpointman1 Eki 2024
- CVE-2019-1696724İzleyin
An issue was discovered in Manager 13.x before 13.0.2.6 and 15.x before 15.0.6 before FreePBX 14.0.10.3.
OrtaCVSS 6,1İstismar yokEPSS %1freepbx · manager21 Eki 2019
- CVE-2019-1696624İzleyin
An issue was discovered in Contactmanager 13.x before 13.0.45.3, 14.x before 14.0.5.12, and 15.x before 15.0.8.21 for FreePBX 14.0.10.3.
OrtaCVSS 6,1İstismar yokEPSS %1freepbx · contactmanager21 Eki 2019
- CVE-2009-180320İzleyin
FreePBX 2.5.1, and other 2.4.x, 2.5.x, and pre-release 2.6.x versions, generates different error messages for a failed login attempt dependi
OrtaCVSS 5,0İstismar yokEPSS %1freepbx · freepbx28 May 2009
- CVE-2018-1589119İzleyin
An issue was discovered in FreePBX core before 3.0.122.43, 14.0.18.34, and 5.0.1beta4.
OrtaCVSS 4,8İstismar yokEPSS %1freepbx · freepbx20 Haz 2019
- CVE-2009-445818İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in FreePBX 2.5.2 and 2.6.0rc2, and possibly other versions, allow remote attackers to in
OrtaCVSS 4,3Kavram kanıtıEPSS %2freepbx · freepbx29 Ara 2009
- CVE-2009-180117İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in FreePBX 2.5.1, and other 2.4.x, 2.5.x, and pre-release 2.6.x versions, allow remote a
OrtaCVSS 4,3İstismar yokEPSS %1freepbx · freepbx28 May 2009
- CVE-2018-1589217İzleyin
FreePBX 13 and 14 has SQL Injection in the DISA module via the hangup variable on the /admin/config.php?display=disa&view=form page.
OrtaCVSS 4,3İstismar yokEPSS %1freepbx · disa20 Haz 2019