İçeriğe atla
Noroxi

FusionPBX kayıtları

fusionpbx üreticisine ait 52 yayımlanmış kayıt.

Tüm kayıtlar

52 kayıt
  • CVE-2019-11409
    61Bu hafta

    app/operator_panel/exec.php in the Operator Panel module in FusionPBX 4.4.3 suffers from a command injection vulnerability due to a lack of

    YüksekCVSS 8,8SilahlaştırılmışEPSS %87

    fusionpbx · fusionpbx17 Haz 2019

  • CVE-2021-43405
    46Planlayın

    An issue was discovered in FusionPBX before 4.5.30.

    YüksekCVSS 8,8Kavram kanıtıEPSS %36

    fusionpbx · fusionpbx5 Kas 2021

  • CVE-2022-35153
    40Planlayın

    FusionPBX 5.0.1 was discovered to contain a command injection vulnerability via /fax/fax_send.php.

    KritikCVSS 9,8İstismar yokEPSS %2

    fusionpbx · fusionpbx18 Ağu 2022

  • CVE-2019-15029
    39İzleyin

    FusionPBX 4.4.8 allows an attacker to execute arbitrary system commands by submitting a malicious command to the service_edit.php file (whic

    YüksekCVSS 8,8Kavram kanıtıEPSS %12

    fusionpbx · fusionpbx5 Eyl 2019

  • CVE-2022-28055
    39İzleyin

    Fusionpbx v4.4 and below contains a command injection vulnerability via the download email logs function.

    KritikCVSS 9,8İstismar yokEPSS %2

    fusionpbx · fusionpbx3 May 2022

  • CVE-2019-16964
    36İzleyin

    app/call_centers/cmd.php in the Call Center Queue Module in FusionPBX up to 4.5.7 suffers from a command injection vulnerability due to a la

    YüksekCVSS 8,8İstismar yokEPSS %2

    fusionpbx · fusionpbx21 Eki 2019

  • CVE-2019-16980
    35İzleyin

    In FusionPBX up to v4.5.7, the file app\call_broadcast\call_broadcast_edit.php uses an unsanitized "id" variable coming from the URL in an u

    YüksekCVSS 8,8İstismar yokEPSS %1

    fusionpbx · fusionpbx21 Eki 2019

  • CVE-2021-43404
    35İzleyin

    An issue was discovered in FusionPBX before 4.5.30.

    YüksekCVSS 8,8İstismar yokEPSS %1

    fusionpbx · fusionpbx5 Kas 2021

  • CVE-2021-43406
    35İzleyin

    An issue was discovered in FusionPBX before 4.5.30.

    YüksekCVSS 8,8İstismar yokEPSS %1

    fusionpbx · fusionpbx5 Kas 2021

  • CVE-2020-21057
    32İzleyin

    Directory Traversal vulnerability in FusionPBX 4.5.7, which allows a remote malicious user to delete folders on the system via the folder va

    YüksekCVSS 8,1İstismar yokEPSS %2

    fusionpbx · fusionpbx20 May 2021

  • CVE-2019-11410
    29İzleyin

    app/backup/index.php in the Backup Module in FusionPBX 4.4.3 suffers from a command injection vulnerability due to a lack of input validatio

    YüksekCVSS 7,2İstismar yokEPSS %3

    fusionpbx · fusionpbx17 Haz 2019

  • CVE-2019-16965
    29İzleyin

    resources/cmd.php in FusionPBX up to 4.5.7 suffers from a command injection vulnerability due to a lack of input validation, which allows au

    YüksekCVSS 7,2İstismar yokEPSS %3

    fusionpbx · fusionpbx21 Eki 2019

  • CVE-2019-11407
    28İzleyin

    app/operator_panel/index_inc.php in the Operator Panel module in FusionPBX 4.4.3 suffers from an information disclosure vulnerability due to

    YüksekCVSS 7,2İstismar yokEPSS %2

    fusionpbx · fusionpbx17 Haz 2019

  • CVE-2019-11408
    26İzleyin

    XSS in app/operator_panel/index_inc.php in the Operator Panel module in FusionPBX 4.4.3 allows remote unauthenticated attackers to inject ar

    OrtaCVSS 6,1Kavram kanıtıEPSS %7

    fusionpbx · fusionpbx17 Haz 2019

  • CVE-2019-16986
    26İzleyin

    In FusionPBX up to v4.5.7, the file resources\download.php uses an unsanitized "f" variable coming from the URL, which takes any pathname an

    OrtaCVSS 6,5İstismar yokEPSS %1

    fusionpbx · fusionpbx21 Eki 2019

  • CVE-2019-16990
    26İzleyin

    In FusionPBX up to v4.5.7, the file app/music_on_hold/music_on_hold.php uses an unsanitized "file" variable coming from the URL, which takes

    OrtaCVSS 6,5İstismar yokEPSS %1

    fusionpbx · fusionpbx21 Eki 2019

  • CVE-2020-21055
    26İzleyin

    A Directory Traversal vulnerability exists in FusionPBX 4.5.7 allows malicoius users to rename any file of the system.via the (1) folder, (2

    OrtaCVSS 6,5İstismar yokEPSS %1

    fusionpbx · fusionpbx20 May 2021

  • CVE-2019-16985
    26İzleyin

    In FusionPBX up to v4.5.7, the file app\xml_cdr\xml_cdr_delete.php uses an unsanitized "rec" variable coming from the URL, which is base64 d

    OrtaCVSS 6,5İstismar yokEPSS %1

    fusionpbx · fusionpbx21 Eki 2019

  • CVE-2021-43403
    26İzleyin

    An issue was discovered in FusionPBX before 4.5.30.

    OrtaCVSS 6,5İstismar yokEPSS %1

    fusionpbx · fusionpbx28 Eyl 2022

  • CVE-2019-19387
    24İzleyin

    A cross-site scripting (XSS) vulnerability in app/fifo_list/fifo_interactive.php in FusionPBX 4.4.1 allows remote attackers to inject arbitr

    OrtaCVSS 6,1İstismar yokEPSS %1

    fusionpbx · fusionpbx28 Kas 2019

  • CVE-2019-19386
    24İzleyin

    A cross-site scripting (XSS) vulnerability in app/voicemail_greetings/voicemail_greeting_edit.php in FusionPBX 4.4.1 allows remote attackers

    OrtaCVSS 6,1İstismar yokEPSS %1

    fusionpbx · fusionpbx28 Kas 2019

  • CVE-2019-19366
    24İzleyin

    A cross-site scripting (XSS) vulnerability in app/xml_cdr/xml_cdr_search.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary

    OrtaCVSS 6,1İstismar yokEPSS %1

    fusionpbx · fusionpbx27 Kas 2019

  • CVE-2019-19367
    24İzleyin

    A cross-site scripting (XSS) vulnerability in app/fax/fax_files.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary web scrip

    OrtaCVSS 6,1İstismar yokEPSS %1

    fusionpbx · fusionpbx27 Kas 2019

  • CVE-2019-19384
    24İzleyin

    A cross-site scripting (XSS) vulnerability in app/fax/fax_log_view.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary web sc

    OrtaCVSS 6,1İstismar yokEPSS %1

    fusionpbx · fusionpbx28 Kas 2019

  • CVE-2019-19385
    24İzleyin

    A cross-site scripting (XSS) vulnerability in app/dialplans/dialplans.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary web

    OrtaCVSS 6,1İstismar yokEPSS %1

    fusionpbx · fusionpbx28 Kas 2019