CVE-2013-4467

VICIDIAL < 2.7 - SQL Injection via Campaign Variable in SCRIPT_multirecording_AJAX.php

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2013-4467. PoCs published by Metasploit, including Metasploit module exploits/unix/webapp/vicidial_manager_send_cmd_exec.

AI-analyzed exploit summary This Metasploit module exploits a command injection vulnerability in VICIdial's manager_send.php, leveraging SQL injection to bypass session checks and execute arbitrary commands. It includes authentication bypass via default credentials and session creation if necessary.

Description

Multiple SQL injection vulnerabilities in the agent interface (agc/) in VICIDIAL dialer (aka Asterisk GUI client) 2.8-403a, 2.7, 2.7RC1, and earlier allow (1) remote attackers to execute arbitrary SQL commands via the campaign variable in SCRIPT_multirecording_AJAX.php, (2) remote authenticated users to execute arbitrary SQL commands via the server_ip parameter to manager_send.php, or (3) other unspecified vectors. NOTE: some of these details are obtained from third party information.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotelinux
https://www.exploit-db.com/exploits/29513

This Metasploit module exploits a command injection vulnerability in VICIdial's manager_send.php, leveraging SQL injection to bypass session checks and execute arbitrary commands. It includes authentication bypass via default credentials and session creation if necessary.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: VICIdial (versions 2.7RC1, 2.7, 2.8-403a, and likely others)
Auth required
Prerequisites: Network access to the VICIdial web interface · Default or valid credentials for VICIdial or astGUIcient
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC EXCELLENT
rubypocunix
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/unix/webapp/vicidial_manager_send_cmd_exec.rb

This Metasploit module exploits an OS command injection vulnerability in VICIdial's manager_send.php via unsanitized input passed to PHP's passthru() function. It also leverages a SQL injection to bypass session checks and includes default credentials for authentication.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: VICIdial (versions 2.7RC1, 2.7, 2.8-403a, and likely others)
Auth required
Prerequisites: Valid VICIdial credentials (default: VDCL/donotedit or VDAD/donotedit) · Valid session or astGUIcient credentials to create one
devstral-2 · analyzed Apr 30, 2026 Full analysis →

References (8)

Core 8
Core References
Exploit, Third Party Advisory exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/29513
Exploit mailing-list x_refsource_mlist
http://seclists.org/oss-sec/2013/q4/175
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/63340
Exploit mailing-list x_refsource_mlist
http://seclists.org/oss-sec/2013/q4/171
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/55453
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/98903

Scores

EPSS 0.7829
EPSS Percentile 99.1%

Details

CWE
CWE-89
Status published
Products (3)
vicidial/vicidial 2.7 rc1
vicidial/vicidial 2.8 403a
vicidial/vicidial < 2.7
Published Mar 11, 2014
Tracked Since Feb 18, 2026