CVE-2013-4468

VICIDIAL dialer <2.8-403a, 2.7, 2.7RC1 - Command Injection

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2013-4468. PoCs published by Metasploit, including Metasploit module exploits/unix/webapp/vicidial_manager_send_cmd_exec.

AI-analyzed exploit summary This Metasploit module exploits a command injection vulnerability in VICIdial's manager_send.php, leveraging SQL injection to bypass session checks and execute arbitrary commands. It includes authentication bypass via default credentials and session creation if necessary.

Description

VICIDIAL dialer (aka Asterisk GUI client) 2.8-403a, 2.7, 2.7RC1, and earlier allows remote authenticated users to execute arbitrary commands via shell metacharacters in the extension parameter in an OriginateVDRelogin action to manager_send.php.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotelinux
https://www.exploit-db.com/exploits/29513

This Metasploit module exploits a command injection vulnerability in VICIdial's manager_send.php, leveraging SQL injection to bypass session checks and execute arbitrary commands. It includes authentication bypass via default credentials and session creation if necessary.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: VICIdial (versions 2.7RC1, 2.7, 2.8-403a, and likely others)
Auth required
Prerequisites: Network access to the VICIdial web interface · Default or valid credentials for VICIdial or astGUIcient
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC EXCELLENT
rubypocunix
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/unix/webapp/vicidial_manager_send_cmd_exec.rb

This Metasploit module exploits a command injection vulnerability in VICIdial's manager_send.php, leveraging SQL injection to bypass session checks and execute arbitrary commands via the 'extension' parameter. It includes functionality to create a session if none exists using astGUIcient credentials.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: VICIdial 2.7RC1, 2.7, 2.8-403a
Auth required
Prerequisites: Valid VICIdial credentials (default: VDCL/donotedit or VDAD/donotedit) · Valid astGUIcient credentials (optional, for session creation)
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (4)

Core 4
Core References
Exploit mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2013/10/23/10
Exploit mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2013/10/25/1
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/29513

Scores

EPSS 0.3176
EPSS Percentile 98.1%

Details

Status published
Products (2)
vicidial/vicidial 2.7 (2 CPE variants)
vicidial/vicidial < 2.8
Published May 14, 2014
Tracked Since Feb 18, 2026