reminders/index.php in Incredible PBX 11 2.0.6.5.0 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the (1) APPTMIN, (2) APPTHR, (3) APPTDA, (4) APPTMO, (5) APPTYR, or (6) APPTPHONE parameters.
References
Link | Resource |
---|---|
http://seclists.org/fulldisclosure/2014/Oct/101 | Exploit |
Configurations
Information
Published : 2014-11-20 05:55
Updated : 2014-11-20 07:09
NVD link : CVE-2014-9001
Mitre link : CVE-2014-9001
JSON object : View
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')
Products Affected
incrediblepbx
- incredible_pbx_11