CVE-2014-5109

Fonality trixbox - SQL Injection via mac Parameter in endpoint_generic.php

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2014-5109. PoCs published by AtT4CKxT3rR0r1ST.

AI-analyzed exploit summary The exploit demonstrates an SQL injection vulnerability in Trixbox's endpoint_generic.php file, allowing an attacker to execute arbitrary SQL queries. The provided URL manipulates the 'mac' parameter to perform a UNION-based SQL injection.

Description

SQL injection vulnerability in maint/modules/endpointcfg/endpoint_generic.php in Fonality trixbox allows remote attackers to execute arbitrary SQL commands via the mac parameter in a Submit action.

Exploits (1)

exploitdb WORKING POC VERIFIED
by AtT4CKxT3rR0r1ST · textwebappsphp
https://www.exploit-db.com/exploits/39347

The exploit demonstrates an SQL injection vulnerability in Trixbox's endpoint_generic.php file, allowing an attacker to execute arbitrary SQL queries. The provided URL manipulates the 'mac' parameter to perform a UNION-based SQL injection.

Classification
Working Poc 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: Trixbox (version not specified)
No auth needed
Prerequisites: Network access to the target application
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References

Scores

EPSS 0.0341
EPSS Percentile 87.3%

Details

CWE
CWE-89
Status published
Products (1)
netfortris/trixbox
Published Jul 28, 2014
Tracked Since Feb 18, 2026