Mark J Crane
14 exploits
Active since Jun 2019
FusionPBX < 4.5.7 - Path Traversal via Unsanitized Download Parameter
CVSS 6.5
FusionPBX 4.4.3 - Command Injection
CVSS 7.2
FusionPBX < 4.5.7 - Authenticated OS Command Injection in Call Center Queue Module
CVSS 8.8
FusionPBX < 4.5.7 - Authenticated OS Command Injection via cmd.php
CVSS 7.2
FusionPBX < 4.5.7 - Cross-Site Scripting via Unsanitized 'c' URL Parameter
CVSS 6.1
FusionPBX < 4.5.7 - Cross-Site Scripting via Device Settings ID Parameter
CVSS 6.1
FusionPBX < 4.5.7 - Cross-Site Scripting via Unsanitized ID Parameter
CVSS 6.1
FusionPBX < 4.5.7 - Cross-Site Scripting via Unsanitized Filename Parameter
CVSS 6.1
FusionPBX < 4.5.7 - Path Traversal via Unsanitized Download Parameter
CVSS 6.5
FusionPBX < 4.5.7 - Cross-Site Scripting via Unsanitized URL Parameter
CVSS 6.1
FusionPBX 4.4.1 - Cross-Site Scripting via Fax UUID Parameter
CVSS 6.1
FusionPBX 4.4.1 - Cross-Site Scripting via Voicemail Greeting Edit Parameters
CVSS 6.1
FusionPBX 4.4.1 - Cross-Site Scripting via dialplan_uuid Parameter
CVSS 6.1
FusionPBX 4.5.7 - Cross-Site Scripting via Unsanitized 'f' Variable
CVSS 6.1