Vulnerability index

Browse CVEs

50 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.2 CVE-2019-16965 resources/cmd.php in FusionPBX up to 4.5.7 suffers from a command injection vulnerability due to a lack of input validation, which allows authenticat… Fusionpbx after 4.5.7 Fix from $1,9502019-10-21 MEDIUM 6.5 CVE-2019-16985 In FusionPBX up to v4.5.7, the file app\xml_cdr\xml_cdr_delete.php uses an unsanitized "rec" variable coming from the URL, which is base64 decoded an… Fusionpbx after 4.5.7 Fix from $1,6002019-10-21 MEDIUM 6.5 CVE-2019-16986 In FusionPBX up to v4.5.7, the file resources\download.php uses an unsanitized "f" variable coming from the URL, which takes any pathname and allows … Fusionpbx after 4.5.7 Fix from $1,6002019-10-21 MEDIUM 6.1 CVE-2019-16987 In FusionPBX up to v4.5.7, the file app\contacts\contact_import.php uses an unsanitized "query_string" variable coming from the URL, which is reflect… Fusionpbx after 4.5.7 Fix from $1,6002019-10-21 MEDIUM 6.1 CVE-2019-16988 In FusionPBX up to v4.5.7, the file app\basic_operator_panel\resources\content.php uses an unsanitized "eavesdrop_dest" variable coming from the URL,… Fusionpbx after 4.5.7 Fix from $1,6002019-10-21 MEDIUM 6.1 CVE-2019-16989 In FusionPBX up to v4.5.7, the file app\conferences_active\conference_interactive.php uses an unsanitized "c" variable coming from the URL, which is … Fusionpbx after 4.5.7 Fix from $1,6002019-10-21 MEDIUM 6.1 CVE-2019-16991 In FusionPBX up to v4.5.7, the file app\edit\filedelete.php uses an unsanitized "file" variable coming from the URL, which is reflected in HTML, lead… Fusionpbx after 4.5.7 Fix from $1,6002019-10-21 MEDIUM 6.1 CVE-2019-16981 In FusionPBX up to v4.5.7, the file app\conference_profiles\conference_profile_params.php uses an unsanitized "id" variable coming from the URL, whic… Fusionpbx after 4.5.7 Fix from $1,6002019-10-21 MEDIUM 6.1 CVE-2019-16982 In FusionPBX up to v4.5.7, the file app\access_controls\access_control_nodes.php uses an unsanitized "id" variable coming from the URL, which is refl… Fusionpbx after 4.5.7 Fix from $1,6002019-10-21 MEDIUM 6.1 CVE-2019-16983 In FusionPBX up to v4.5.7, the file resources\paging.php has a paging function (called by several pages of the interface), which uses an unsanitized … Fusionpbx after 4.5.7 Fix from $1,6002019-10-21 MEDIUM 6.1 CVE-2019-16984 In FusionPBX up to v4.5.7, the file app\recordings\recording_play.php uses an unsanitized "filename" variable coming from the URL, which is base64 de… Fusionpbx after 4.5.7 Fix from $1,6002019-10-21 HIGH 8.8 CVE-2019-16980 In FusionPBX up to v4.5.7, the file app\call_broadcast\call_broadcast_edit.php uses an unsanitized "id" variable coming from the URL in an unparamete… Fusionpbx after 4.5.7 Fix from $1,9502019-10-21 MEDIUM 6.5 CVE-2019-16990 In FusionPBX up to v4.5.7, the file app/music_on_hold/music_on_hold.php uses an unsanitized "file" variable coming from the URL, which takes any path… Fusionpbx after 4.5.7 Fix from $1,6002019-10-21 MEDIUM 6.1 CVE-2019-16978 In FusionPBX up to v4.5.7, the file app\devices\device_settings.php uses an unsanitized "id" variable coming from the URL, which is reflected on 2 oc… Fusionpbx after 4.5.7 Fix from $1,6002019-10-21 MEDIUM 6.1 CVE-2019-16979 In FusionPBX up to v4.5.7, the file app\contacts\contact_urls.php uses an unsanitized "id" variable coming from the URL, which is reflected in HTML, … Fusionpbx after 4.5.7 Fix from $1,6002019-10-21 HIGH 8.8 CVE-2019-15029EPSS 12% FusionPBX 4.4.8 allows an attacker to execute arbitrary system commands by submitting a malicious command to the service_edit.php file (which will in… Fusionpbx No fix yet Fix from $1,9502019-09-05 HIGH 8.8 CVE-2019-11409EPSS 87% app/operator_panel/exec.php in the Operator Panel module in FusionPBX 4.4.3 suffers from a command injection vulnerability due to a lack of input val… Fusionpbx Patch available Fix from $1,9502019-06-17 HIGH 7.2 CVE-2019-11410 app/backup/index.php in the Backup Module in FusionPBX 4.4.3 suffers from a command injection vulnerability due to a lack of input validation, which … Fusionpbx Patch available Fix from $1,9502019-06-17 HIGH 7.2 CVE-2019-11407 app/operator_panel/index_inc.php in the Operator Panel module in FusionPBX 4.4.3 suffers from an information disclosure vulnerability due to excessiv… Fusionpbx Patch available Fix from $1,9502019-06-17 MEDIUM 6.1 CVE-2019-11408EPSS 7% XSS in app/operator_panel/index_inc.php in the Operator Panel module in FusionPBX 4.4.3 allows remote unauthenticated attackers to inject arbitrary J… Fusionpbx Patch available Fix from $1,6002019-06-17