PT-2018-5680 · Fonality · Trixbox
Publicado
2018-02-16
·
Atualizado
2022-02-19
·
CVE-2017-14535
CVSS v2.0
9.0
Alta
| Vetor | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
trixbox version 2.8.0.4
Description:
The issue is related to OS command injection via shell metacharacters in the
lang parameter to the "/maint/modules/home/index.php" API endpoint. This allows for potential exploitation.Recommendations:
For trixbox version 2.8.0.4, as a temporary workaround, consider restricting access to the "/maint/modules/home/index.php" API endpoint or sanitizing the
lang parameter to prevent shell metacharacter injection until a patch is available.Exploit
Correção
OS Command Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Trixbox