CVE-2013-4468
VICIDIAL dialer <2.8-403a, 2.7, 2.7RC1 - Command Injection
Title source: llmDescription
VICIDIAL dialer (aka Asterisk GUI client) 2.8-403a, 2.7, 2.7RC1, and earlier allows remote authenticated users to execute arbitrary commands via shell metacharacters in the extension parameter in an OriginateVDRelogin action to manager_send.php.
Exploits (2)
metasploit
WORKING POC
EXCELLENT
rubypocunix
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/unix/webapp/vicidial_manager_send_cmd_exec.rb
exploitdb
WORKING POC
VERIFIED
by Metasploit · rubyremotelinux
https://www.exploit-db.com/exploits/29513
Scores
EPSS
0.8244
EPSS Percentile
99.2%
Classification
Status
draft
Affected Products (3)
vicidial/vicidial
< 2.8
vicidial/vicidial
vicidial/vicidial
Timeline
Published
May 14, 2014
Tracked Since
Feb 18, 2026