CVE-2013-4468

VICIDIAL dialer <2.8-403a, 2.7, 2.7RC1 - Command Injection

Title source: llm

Description

VICIDIAL dialer (aka Asterisk GUI client) 2.8-403a, 2.7, 2.7RC1, and earlier allows remote authenticated users to execute arbitrary commands via shell metacharacters in the extension parameter in an OriginateVDRelogin action to manager_send.php.

Exploits (2)

metasploit WORKING POC EXCELLENT
rubypocunix
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/unix/webapp/vicidial_manager_send_cmd_exec.rb
exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotelinux
https://www.exploit-db.com/exploits/29513

Scores

EPSS 0.8244
EPSS Percentile 99.2%

Classification

Status draft

Affected Products (3)

vicidial/vicidial < 2.8
vicidial/vicidial
vicidial/vicidial

Timeline

Published May 14, 2014
Tracked Since Feb 18, 2026