CVE-2014-5111

NUCLEI

Netfortris Trixbox - Path Traversal

Title source: rule

Description

Multiple directory traversal vulnerabilities in Fonality trixbox allow remote attackers to read arbitrary files via a .. (dot dot) in the lang parameter to (1) home/index.php, (2) asterisk_info/asterisk_info.php, (3) repo/repo.php, or (4) endpointcfg/endpointcfg.php in maint/modules/.

Exploits (4)

exploitdb WRITEUP VERIFIED
by AtT4CKxT3rR0r1ST · textwebappsphp
https://www.exploit-db.com/exploits/39350
exploitdb WRITEUP VERIFIED
by AtT4CKxT3rR0r1ST · textwebappsphp
https://www.exploit-db.com/exploits/39348
exploitdb WRITEUP VERIFIED
by AtT4CKxT3rR0r1ST · textwebappsphp
https://www.exploit-db.com/exploits/39351
exploitdb WRITEUP VERIFIED
by AtT4CKxT3rR0r1ST · textwebappsphp
https://www.exploit-db.com/exploits/39349

Nuclei Templates (1)

Fonality trixbox - Local File Inclusion
MEDIUMby daffainfo

Scores

EPSS 0.6772
EPSS Percentile 98.6%

Details

CWE
CWE-22
Status published
Products (1)
netfortris/trixbox
Published Jul 28, 2014
Tracked Since Feb 18, 2026