CVE-2013-4468

VICIDIAL dialer <2.8-403a, 2.7, 2.7RC1 - Command Injection

Title source: llm

Description

VICIDIAL dialer (aka Asterisk GUI client) 2.8-403a, 2.7, 2.7RC1, and earlier allows remote authenticated users to execute arbitrary commands via shell metacharacters in the extension parameter in an OriginateVDRelogin action to manager_send.php.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotelinux
https://www.exploit-db.com/exploits/29513
metasploit WORKING POC EXCELLENT
rubypocunix
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/unix/webapp/vicidial_manager_send_cmd_exec.rb

Scores

EPSS 0.8244
EPSS Percentile 99.2%

Details

Status published
Products (2)
vicidial/vicidial 2.7 (2 CPE variants)
vicidial/vicidial < 2.8
Published May 14, 2014
Tracked Since Feb 18, 2026