CVE-2008-6825

trixbox < 2.6.1 - Remote File Inclusion via langChoice Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 4 public exploits for CVE-2008-6825. PoCs published by Metasploit, muts, Jean-Michel BESNARD, including Metasploit module exploits/unix/webapp/trixbox_langchoice.

AI-analyzed exploit summary This Metasploit module exploits a PHP Local File Inclusion vulnerability in Trixbox CE 2.6.1 by injecting malicious PHP code into the session file and then executing it via the langChoice parameter.

Description

Directory traversal vulnerability in user/index.php in Fonality trixbox CE 2.6.1 and earlier allows remote attackers to include and execute arbitrary files via a .. (dot dot) in the langChoice parameter.

Exploits (4)

exploitdb WORKING POC VERIFIED
by Metasploit · rubywebappsphp
https://www.exploit-db.com/exploits/16904

This Metasploit module exploits a PHP Local File Inclusion vulnerability in Trixbox CE 2.6.1 by injecting malicious PHP code into the session file and then executing it via the langChoice parameter.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Trixbox CE 2.6.1
No auth needed
Prerequisites: Access to the target's web interface · PHP session handling enabled
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by muts · pythonremotelinux
https://www.exploit-db.com/exploits/6045

This exploit targets a PHP session file inclusion vulnerability in TrixBox 2.6.1 to inject a reverse shell payload via the 'langChoice' parameter. It extracts the session ID, triggers the payload, and establishes a root shell.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: TrixBox 2.6.1
No auth needed
Prerequisites: Network access to the target · PHP session handling enabled · Outbound connectivity for reverse shell
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by Jean-Michel BESNARD · perlwebappslinux
https://www.exploit-db.com/exploits/6026

This exploit targets a directory traversal vulnerability in Trixbox's PHP session handling to achieve remote code execution. It leverages a reverse shell payload via Perl's Socket module, with options for root or asterisk user privileges via sudo.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Trixbox (version not specified, likely pre-2008)
No auth needed
Prerequisites: Network access to the target · PHP session handling vulnerability in Trixbox
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC MANUAL
by chao-mu · rubypocphp
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/unix/webapp/trixbox_langchoice.rb

This Metasploit module exploits a PHP Local File Inclusion vulnerability in Trixbox by injecting malicious PHP code into the session file and then triggering its execution via the langChoice parameter.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Trixbox CE 2.6.1
No auth needed
Prerequisites: Network access to the target · PHP session handling enabled · Default or known path for session files
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/43686
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/6026
Third Party Advisory mailing-list x_refsource_fulldisc
http://archives.neohapsis.com/archives/fulldisclosure/2008-07/0101.html
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/30135
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/50421

Scores

EPSS 0.2027
EPSS Percentile 97.1%

Details

CWE
CWE-22
Status published
Products (3)
trixbox/trixbox 2.0
trixbox/trixbox 2.4.2.0
trixbox/trixbox < 2.6.1
Published Jun 05, 2009
Tracked Since Feb 18, 2026