FusionPBX kayıtları
fusionpbx üreticisine ait 52 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 1 · %1,9
- Pre-auth RCE
- 3
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')32
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')6
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')6
- CWE-116 Improper Encoding or Escaping of Output1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
- CWE-20 Improper Input Validation1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
52 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
61Bu hafta | CVE-2019-11409Silahlaştırılmış | app/operator_panel/exec.php in the Operator Panel module in FusionPBX 4.4.3 suffers from a command injection vulnerability due to a lack of fusionpbx · fusionpbx · CWE-78 | Yüksek8,8 | — | %87,5 | 17 Haz 2019 |
46Planlayın | CVE-2021-43405Kavram kanıtı | An issue was discovered in FusionPBX before 4.5.30.fusionpbx · fusionpbx | Yüksek8,8 | — | %35,6 | 5 Kas 2021 |
40Planlayın | CVE-2022-35153İstismar yok | FusionPBX 5.0.1 was discovered to contain a command injection vulnerability via /fax/fax_send.php.fusionpbx · fusionpbx · CWE-116 | Kritik9,8 | — | %1,8 | 18 Ağu 2022 |
39İzleyin | CVE-2019-15029Kavram kanıtı | FusionPBX 4.4.8 allows an attacker to execute arbitrary system commands by submitting a malicious command to the service_edit.php file (whicfusionpbx · fusionpbx · CWE-78 | Yüksek8,8 | — | %12,3 | 5 Eyl 2019 |
39İzleyin | CVE-2022-28055İstismar yok | Fusionpbx v4.4 and below contains a command injection vulnerability via the download email logs function.fusionpbx · fusionpbx · CWE-78 | Kritik9,8 | — | %1,5 | 3 May 2022 |
36İzleyin | CVE-2019-16964İstismar yok | app/call_centers/cmd.php in the Call Center Queue Module in FusionPBX up to 4.5.7 suffers from a command injection vulnerability due to a lafusionpbx · fusionpbx · CWE-78 | Yüksek8,8 | — | %2,0 | 21 Eki 2019 |
35İzleyin | CVE-2019-16980İstismar yok | In FusionPBX up to v4.5.7, the file app\call_broadcast\call_broadcast_edit.php uses an unsanitized "id" variable coming from the URL in an ufusionpbx · fusionpbx · CWE-89 | Yüksek8,8 | — | %1,2 | 21 Eki 2019 |
35İzleyin | CVE-2021-43404İstismar yok | An issue was discovered in FusionPBX before 4.5.30.fusionpbx · fusionpbx | Yüksek8,8 | — | %1,0 | 5 Kas 2021 |
35İzleyin | CVE-2021-43406İstismar yok | An issue was discovered in FusionPBX before 4.5.30.fusionpbx · fusionpbx · CWE-20 | Yüksek8,8 | — | %1,0 | 5 Kas 2021 |
32İzleyin | CVE-2020-21057İstismar yok | Directory Traversal vulnerability in FusionPBX 4.5.7, which allows a remote malicious user to delete folders on the system via the folder vafusionpbx · fusionpbx · CWE-22 | Yüksek8,1 | — | %1,5 | 20 May 2021 |
29İzleyin | CVE-2019-11410İstismar yok | app/backup/index.php in the Backup Module in FusionPBX 4.4.3 suffers from a command injection vulnerability due to a lack of input validatiofusionpbx · fusionpbx · CWE-78 | Yüksek7,2 | — | %3,4 | 17 Haz 2019 |
29İzleyin | CVE-2019-16965İstismar yok | resources/cmd.php in FusionPBX up to 4.5.7 suffers from a command injection vulnerability due to a lack of input validation, which allows aufusionpbx · fusionpbx · CWE-78 | Yüksek7,2 | — | %3,0 | 21 Eki 2019 |
28İzleyin | CVE-2019-11407İstismar yok | app/operator_panel/index_inc.php in the Operator Panel module in FusionPBX 4.4.3 suffers from an information disclosure vulnerability due tofusionpbx · fusionpbx · CWE-200 | Yüksek7,2 | — | %1,5 | 17 Haz 2019 |
26İzleyin | CVE-2019-11408Kavram kanıtı | XSS in app/operator_panel/index_inc.php in the Operator Panel module in FusionPBX 4.4.3 allows remote unauthenticated attackers to inject arfusionpbx · fusionpbx · CWE-79 | Orta6,1 | — | %6,9 | 17 Haz 2019 |
26İzleyin | CVE-2019-16986İstismar yok | In FusionPBX up to v4.5.7, the file resources\download.php uses an unsanitized "f" variable coming from the URL, which takes any pathname anfusionpbx · fusionpbx · CWE-22 | Orta6,5 | — | %1,4 | 21 Eki 2019 |
26İzleyin | CVE-2019-16990İstismar yok | In FusionPBX up to v4.5.7, the file app/music_on_hold/music_on_hold.php uses an unsanitized "file" variable coming from the URL, which takesfusionpbx · fusionpbx · CWE-22 | Orta6,5 | — | %1,3 | 21 Eki 2019 |
26İzleyin | CVE-2020-21055İstismar yok | A Directory Traversal vulnerability exists in FusionPBX 4.5.7 allows malicoius users to rename any file of the system.via the (1) folder, (2fusionpbx · fusionpbx · CWE-22 | Orta6,5 | — | %1,2 | 20 May 2021 |
26İzleyin | CVE-2019-16985İstismar yok | In FusionPBX up to v4.5.7, the file app\xml_cdr\xml_cdr_delete.php uses an unsanitized "rec" variable coming from the URL, which is base64 dfusionpbx · fusionpbx · CWE-22 | Orta6,5 | — | %1,1 | 21 Eki 2019 |
26İzleyin | CVE-2021-43403İstismar yok | An issue was discovered in FusionPBX before 4.5.30.fusionpbx · fusionpbx | Orta6,5 | — | %0,9 | 28 Eyl 2022 |
24İzleyin | CVE-2019-19387İstismar yok | A cross-site scripting (XSS) vulnerability in app/fifo_list/fifo_interactive.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrfusionpbx · fusionpbx · CWE-79 | Orta6,1 | — | %0,9 | 28 Kas 2019 |
24İzleyin | CVE-2019-19386İstismar yok | A cross-site scripting (XSS) vulnerability in app/voicemail_greetings/voicemail_greeting_edit.php in FusionPBX 4.4.1 allows remote attackersfusionpbx · fusionpbx · CWE-79 | Orta6,1 | — | %0,9 | 28 Kas 2019 |
24İzleyin | CVE-2019-19366İstismar yok | A cross-site scripting (XSS) vulnerability in app/xml_cdr/xml_cdr_search.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary fusionpbx · fusionpbx · CWE-79 | Orta6,1 | — | %0,9 | 27 Kas 2019 |
24İzleyin | CVE-2019-19367İstismar yok | A cross-site scripting (XSS) vulnerability in app/fax/fax_files.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary web scripfusionpbx · fusionpbx · CWE-79 | Orta6,1 | — | %0,9 | 27 Kas 2019 |
24İzleyin | CVE-2019-19384İstismar yok | A cross-site scripting (XSS) vulnerability in app/fax/fax_log_view.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary web scfusionpbx · fusionpbx · CWE-79 | Orta6,1 | — | %0,9 | 28 Kas 2019 |
24İzleyin | CVE-2019-19385İstismar yok | A cross-site scripting (XSS) vulnerability in app/dialplans/dialplans.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary webfusionpbx · fusionpbx · CWE-79 | Orta6,1 | — | %0,9 | 28 Kas 2019 |
- CVE-2019-1140961Bu hafta
app/operator_panel/exec.php in the Operator Panel module in FusionPBX 4.4.3 suffers from a command injection vulnerability due to a lack of
YüksekCVSS 8,8SilahlaştırılmışEPSS %87fusionpbx · fusionpbx17 Haz 2019
- CVE-2021-4340546Planlayın
An issue was discovered in FusionPBX before 4.5.30.
YüksekCVSS 8,8Kavram kanıtıEPSS %36fusionpbx · fusionpbx5 Kas 2021
- CVE-2022-3515340Planlayın
FusionPBX 5.0.1 was discovered to contain a command injection vulnerability via /fax/fax_send.php.
KritikCVSS 9,8İstismar yokEPSS %2fusionpbx · fusionpbx18 Ağu 2022
- CVE-2019-1502939İzleyin
FusionPBX 4.4.8 allows an attacker to execute arbitrary system commands by submitting a malicious command to the service_edit.php file (whic
YüksekCVSS 8,8Kavram kanıtıEPSS %12fusionpbx · fusionpbx5 Eyl 2019
- CVE-2022-2805539İzleyin
Fusionpbx v4.4 and below contains a command injection vulnerability via the download email logs function.
KritikCVSS 9,8İstismar yokEPSS %2fusionpbx · fusionpbx3 May 2022
- CVE-2019-1696436İzleyin
app/call_centers/cmd.php in the Call Center Queue Module in FusionPBX up to 4.5.7 suffers from a command injection vulnerability due to a la
YüksekCVSS 8,8İstismar yokEPSS %2fusionpbx · fusionpbx21 Eki 2019
- CVE-2019-1698035İzleyin
In FusionPBX up to v4.5.7, the file app\call_broadcast\call_broadcast_edit.php uses an unsanitized "id" variable coming from the URL in an u
YüksekCVSS 8,8İstismar yokEPSS %1fusionpbx · fusionpbx21 Eki 2019
- CVE-2021-4340435İzleyin
An issue was discovered in FusionPBX before 4.5.30.
YüksekCVSS 8,8İstismar yokEPSS %1fusionpbx · fusionpbx5 Kas 2021
- CVE-2021-4340635İzleyin
An issue was discovered in FusionPBX before 4.5.30.
YüksekCVSS 8,8İstismar yokEPSS %1fusionpbx · fusionpbx5 Kas 2021
- CVE-2020-2105732İzleyin
Directory Traversal vulnerability in FusionPBX 4.5.7, which allows a remote malicious user to delete folders on the system via the folder va
YüksekCVSS 8,1İstismar yokEPSS %2fusionpbx · fusionpbx20 May 2021
- CVE-2019-1141029İzleyin
app/backup/index.php in the Backup Module in FusionPBX 4.4.3 suffers from a command injection vulnerability due to a lack of input validatio
YüksekCVSS 7,2İstismar yokEPSS %3fusionpbx · fusionpbx17 Haz 2019
- CVE-2019-1696529İzleyin
resources/cmd.php in FusionPBX up to 4.5.7 suffers from a command injection vulnerability due to a lack of input validation, which allows au
YüksekCVSS 7,2İstismar yokEPSS %3fusionpbx · fusionpbx21 Eki 2019
- CVE-2019-1140728İzleyin
app/operator_panel/index_inc.php in the Operator Panel module in FusionPBX 4.4.3 suffers from an information disclosure vulnerability due to
YüksekCVSS 7,2İstismar yokEPSS %2fusionpbx · fusionpbx17 Haz 2019
- CVE-2019-1140826İzleyin
XSS in app/operator_panel/index_inc.php in the Operator Panel module in FusionPBX 4.4.3 allows remote unauthenticated attackers to inject ar
OrtaCVSS 6,1Kavram kanıtıEPSS %7fusionpbx · fusionpbx17 Haz 2019
- CVE-2019-1698626İzleyin
In FusionPBX up to v4.5.7, the file resources\download.php uses an unsanitized "f" variable coming from the URL, which takes any pathname an
OrtaCVSS 6,5İstismar yokEPSS %1fusionpbx · fusionpbx21 Eki 2019
- CVE-2019-1699026İzleyin
In FusionPBX up to v4.5.7, the file app/music_on_hold/music_on_hold.php uses an unsanitized "file" variable coming from the URL, which takes
OrtaCVSS 6,5İstismar yokEPSS %1fusionpbx · fusionpbx21 Eki 2019
- CVE-2020-2105526İzleyin
A Directory Traversal vulnerability exists in FusionPBX 4.5.7 allows malicoius users to rename any file of the system.via the (1) folder, (2
OrtaCVSS 6,5İstismar yokEPSS %1fusionpbx · fusionpbx20 May 2021
- CVE-2019-1698526İzleyin
In FusionPBX up to v4.5.7, the file app\xml_cdr\xml_cdr_delete.php uses an unsanitized "rec" variable coming from the URL, which is base64 d
OrtaCVSS 6,5İstismar yokEPSS %1fusionpbx · fusionpbx21 Eki 2019
- CVE-2021-4340326İzleyin
An issue was discovered in FusionPBX before 4.5.30.
OrtaCVSS 6,5İstismar yokEPSS %1fusionpbx · fusionpbx28 Eyl 2022
- CVE-2019-1938724İzleyin
A cross-site scripting (XSS) vulnerability in app/fifo_list/fifo_interactive.php in FusionPBX 4.4.1 allows remote attackers to inject arbitr
OrtaCVSS 6,1İstismar yokEPSS %1fusionpbx · fusionpbx28 Kas 2019
- CVE-2019-1938624İzleyin
A cross-site scripting (XSS) vulnerability in app/voicemail_greetings/voicemail_greeting_edit.php in FusionPBX 4.4.1 allows remote attackers
OrtaCVSS 6,1İstismar yokEPSS %1fusionpbx · fusionpbx28 Kas 2019
- CVE-2019-1936624İzleyin
A cross-site scripting (XSS) vulnerability in app/xml_cdr/xml_cdr_search.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary
OrtaCVSS 6,1İstismar yokEPSS %1fusionpbx · fusionpbx27 Kas 2019
- CVE-2019-1936724İzleyin
A cross-site scripting (XSS) vulnerability in app/fax/fax_files.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary web scrip
OrtaCVSS 6,1İstismar yokEPSS %1fusionpbx · fusionpbx27 Kas 2019
- CVE-2019-1938424İzleyin
A cross-site scripting (XSS) vulnerability in app/fax/fax_log_view.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary web sc
OrtaCVSS 6,1İstismar yokEPSS %1fusionpbx · fusionpbx28 Kas 2019
- CVE-2019-1938524İzleyin
A cross-site scripting (XSS) vulnerability in app/dialplans/dialplans.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary web
OrtaCVSS 6,1İstismar yokEPSS %1fusionpbx · fusionpbx28 Kas 2019